CVE-2025-3336
published 2025-04-07CVE-2025-3336: A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of…
PriorityP344high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.43%
34.6th percentile
A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/member_save.php. The manipulation of the argument last leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adonesevangelista | online_restaurant_management_system | — | — |
| codeprojects | online_restaurant_management_system | — | — |
| linux | linux_kernel | >= 6.1.159 < 6.1.160 | 6.1.160 |
| linux | linux_kernel | >= 6.12.60 < 6.12.61 | 6.12.61 |
| linux | linux_kernel | >= 6.17.10 < 6.17.11 | 6.17.11 |
| linux | linux_kernel | >= 6.6.119 < 6.6.120 | 6.6.120 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat5.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
mptcp: Initialise rcv_mss before calling tcp_send_active_reset() in mptcp_do_fastclose().
osv·2025-12-16
CVE-2025-68291 mptcp: Initialise rcv_mss before calling tcp_send_active_reset() in mptcp_do_fastclose().
mptcp: Initialise rcv_mss before calling tcp_send_active_reset() in mptcp_do_fastclose().
In the Linux kernel, the following vulnerability has been resolved:
mptcp: Initialise rcv_mss before calling tcp_send_active_reset() in mptcp_do_fastclose().
syzbot reported divide-by-zero in __tcp_select_window() by
MPTCP socket. [0]
We had a similar issue for the bare TCP and fixed in commit
499350a5a6e7 ("tcp: initialize rcv_mss to TCP_MIN_MSS instead
of 0").
Let's apply the same fix to mptcp_do_fastclose().
[0]:
Oops: divide error: 0000 [#1] SMP KASAN PTI
CPU: 0 UID: 0 PID: 6068 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025
RIP: 0010:__tcp_select_window+0x824/0x1320 net/ipv4/tcp_output.c:3336
Co
GHSA
GHSA-7wq2-cp3p-6phc: A vulnerability was found in codeprojects Online Restaurant Management System 1
ghsa_unreviewed·2025-04-07
CVE-2025-3336 [MEDIUM] CWE-74 GHSA-7wq2-cp3p-6phc: A vulnerability was found in codeprojects Online Restaurant Management System 1
A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/member_save.php. The manipulation of the argument last leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-07
Published