CVE-2025-4811: CodeAstro Pharmacy Management System Login index.php sql injection
A vulnerability was found in CodeAstro Pharmacy Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4811?
CVE-2025-4811 has been rated as critical due to the potential for SQL injection.
What component of the CodeAstro Pharmacy Management System is affected by CVE-2025-4811?
CVE-2025-4811 affects the Login component of the CodeAstro Pharmacy Management System, specifically the /index.php file.
How does CVE-2025-4811 exploit SQL injection?
CVE-2025-4811 exploits SQL injection through manipulation of the Username argument.
How can I mitigate the risk posed by CVE-2025-4811?
Mitigation of CVE-2025-4811 involves sanitizing user inputs and implementing proper parameterized queries.
Which version of the CodeAstro Pharmacy Management System is vulnerable to CVE-2025-4811?
CVE-2025-4811 affects CodeAstro Pharmacy Management System version 1.0.