CVE-2025-8930: code-projects Medical Store Management System Update Company UpdateCompany.java sql injection
A vulnerability was found in code-projects Medical Store Management System 1.0. This issue affects some unknown processing of the file UpdateCompany.java of the component Update Company Page. The manipulation of the argument companyNameTxt leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8930?
CVE-2025-8930 is classified as a high severity vulnerability due to its potential for SQL injection, which can lead to unauthorized database access.
How do I fix CVE-2025-8930?
To fix CVE-2025-8930, ensure proper input validation and parameterized queries in the UpdateCompany.java file to prevent SQL injection.
What component is affected by CVE-2025-8930?
CVE-2025-8930 affects the Update Company Page component of the Medical Store Management System.
What is the nature of the attack vector in CVE-2025-8930?
The attack vector for CVE-2025-8930 involves manipulating the companyNameTxt argument to exploit SQL injection vulnerabilities.
Which software version is impacted by CVE-2025-8930?
CVE-2025-8930 impacts the Medical Store Management System version 1.0 developed by code-projects.