CVE-2025-8502: code-projects Online Medicine Guide changepass.php sql injection
A vulnerability classified as critical was found in code-projects Online Medicine Guide 1.0. Affected by this vulnerability is an unknown functionality of the file /changepass.php. The manipulation of the argument ups leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8502?
CVE-2025-8502 is classified as a critical vulnerability.
How do I fix CVE-2025-8502?
To fix CVE-2025-8502, update the Online Medicine Guide software to the latest version that addresses the SQL injection vulnerability.
What types of attacks are possible with CVE-2025-8502?
CVE-2025-8502 allows for remote SQL injection attacks through manipulation of the ups argument in the /changepass.php file.
Which software is affected by CVE-2025-8502?
CVE-2025-8502 affects the Online Medicine Guide version 1.0 developed by code-projects.
Can CVE-2025-8502 be exploited remotely?
Yes, CVE-2025-8502 can be exploited remotely, making it a significant security risk.