CVE-2025-11609

Severity
6.3MEDIUM
EPSS
0.2%
top 58.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11

Description

A flaw has been found in code-projects Hospital Management System 1.0. Affected is the function session of the component express-session. This manipulation of the argument secret with the input secret causes use of hard-coded cryptographic key . The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been published and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
code-projects Hospital Management System express-session hard-coded key2025-10-11
GHSA
GHSA-7xf9-rcmv-fcpj: A flaw has been found in code-projects Hospital Management System 12025-10-11

📋Vendor Advisories

1
Microsoft
An issue was discovered in the stv06xx subsystem in the Linux kernel before 5.6.1. drivers/media/usb/gspca/stv06xx/stv06xx.c and drivers/media/usb/gspca/stv06xx/stv06xx_pb0100.c mishandle invalid desc2020-04-14
CVE-2025-11609 (MEDIUM CVSS 6.3) | A flaw has been found in code-proje | cvebase.io