First published: Thu Apr 03 2025(Updated: )
A vulnerability was found in SourceCodester Online Medicine Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file /view_category.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sourcecodester Online Medicine Ordering System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3140 has been classified as critical due to its potential for remote exploitation.
CVE-2025-3140 is a SQL injection vulnerability affecting the /view_category.php file.
CVE-2025-3140 can be exploited by manipulating the ID parameter in the URL.
Fixing CVE-2025-3140 involves sanitizing user inputs and using prepared statements in database queries.
CVE-2025-3140 affects the SourceCodester Online Medicine Ordering System version 1.0.