MEDIUM
code-projects Online Medicine Guide addelidetails.php sql injection
Published Aug 10, 2025
6.9
MEDIUMCVSS 4.0
EPSS 0.43%
Description
A vulnerability classified as critical has been found in code-projects Online Medicine Guide 1.0. Affected is an unknown function of the file /addelidetails.php. The manipulation of the argument del leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected products
-
- Version 1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Code-Projects | Online Medicine Guide | n/a |
|
- 1.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://code-projects.org/ product
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-24091 Advisory
- https://github.com/Find33-3/cve/issues/1 exploitissue-trackingIssue Tracking
- https://vuldb.com/?ctiid.319338 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.319338 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.627335 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://code-projects.org/ | product | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-24091 | Advisory | |
| https://github.com/Find33-3/cve/issues/1 | exploitissue-trackingIssue Tracking | |
| https://vuldb.com/?ctiid.319338 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.319338 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.627335 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 10, 2025
Updated Aug 13, 2025
Reserved Aug 9, 2025
Link CVE-2025-8809
CISA Vulnrichment
Updated Aug 13, 2025
ENISA EUVD
EUVD-2025-24091 Assigner VulDB
Published Aug 10, 2025
Updated Aug 13, 2025
Exploited since n/a
Link EUVD-2025-24091