PT-2025-19708 · Sourcecodester · Sourcecodester Web-Based Pharmacy Product Management System
Published
2025-05-05
·
Updated
2025-05-05
·
CVE-2025-45751
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SourceCodester Web Based Pharmacy Product Management System version 1.0
Description
The issue concerns Cross Site Scripting (XSS) in the add-admin.php file via the
Fullname text field. This allows for potential malicious script injection.Recommendations
For SourceCodester Web Based Pharmacy Product Management System version 1.0, consider validating and sanitizing user input in the
Fullname field to prevent XSS attacks. As a temporary workaround, restrict access to the add-admin.php file until a proper fix is implemented.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Web-Based Pharmacy Product Management System