CVE-2025-3822: SourceCodester Web-based Pharmacy Product Management System changepassword.php cross site scripting
A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file changepassword.php. The manipulation of the argument txtconfirmpassword/txtnewpassword/txtoldpassword leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3822?
CVE-2025-3822 has been rated as problematic.
What does CVE-2025-3822 affect?
CVE-2025-3822 affects the file changepassword.php in the SourceCodester Web-based Pharmacy Product Management System.
What is the nature of the vulnerability in CVE-2025-3822?
CVE-2025-3822 involves manipulation of arguments related to password changes which could lead to potential unauthorized access.
How do I fix CVE-2025-3822?
To fix CVE-2025-3822, ensure proper validation and sanitization of user input in the changepassword.php file.
Is CVE-2025-3822 a known vulnerability?
Yes, CVE-2025-3822 is a known vulnerability affecting the SourceCodester Web-based Pharmacy Product Management System.