CVE-2025-3696: SourceCodester Web-based Pharmacy Product Management System search_stock. php sql injection
A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unknown code of the file /search/searchstock. php. The manipulation of the argument Name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3696?
CVE-2025-3696 is classified as a critical vulnerability.
How does CVE-2025-3696 affect the system?
CVE-2025-3696 affects the '/search/search_stock.php' file and allows for SQL injection through the 'Name' argument.
How do I fix CVE-2025-3696?
To fix CVE-2025-3696, ensure that proper input validation and prepared statements are implemented in the affected code.
Who is affected by CVE-2025-3696?
CVE-2025-3696 affects users of the SourceCodester Web-based Pharmacy Product Management System version 1.0.
What type of attack can be initiated through CVE-2025-3696?
Through CVE-2025-3696, an attacker can initiate a SQL injection attack.