CVE-2025-3694: SourceCodester Web-based Pharmacy Product Management System Login sql injection
A vulnerability classified as critical has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part of the component Login Handler. The manipulation of the argument loginemail leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3694?
CVE-2025-3694 is classified as a critical vulnerability.
What type of vulnerability is CVE-2025-3694?
CVE-2025-3694 is a SQL injection vulnerability affecting the Login Handler component.
How can I exploit CVE-2025-3694?
CVE-2025-3694 can potentially be exploited by manipulating the login_email argument in the application.
How do I fix CVE-2025-3694?
To fix CVE-2025-3694, sanitize user inputs and use prepared statements for database queries.
What software is affected by CVE-2025-3694?
CVE-2025-3694 affects SourceCodester Web-based Pharmacy Product Management System version 1.0.