github.comexploit
https://github.com/6s6-630/CVE/blob/main/yaofang.md CVE-2025-3244
MEDIUM
SourceCodester Web-based Pharmacy Product Management System Create User Page add-admin.php unrestricted upload
Record summary
CVE-2025-3244 has a selected CVSS score of 5.3 (medium).
Description
A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add-admin.php of the component Create User Page. The manipulation of the argument Avatar leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 4, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Web-based Pharmacy Product Management SystemBrowse SourceCodester / Web-based Pharmacy Product Management System | CVE List | 1.0 | affected |
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-3244 VDB-303271 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.303271 VDB-303271 | SourceCodester Web-based Pharmacy Product Management System Create User Page add-admin.php unrestricted uploadvdb entryTechnical description
https://vuldb.com/?id.303271 Submit #547916 | sourcecodester Web-based Pharmacy Product Management System using PHP and MySQL Database 1.0 RCEThird-party advisory
https://vuldb.com/?submit.547916 sourcecodester.comproduct
https://www.sourcecodester.com/