Severity
6.9MEDIUMNVD
EPSS
0.0%
top 86.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 1
Latest updateApr 8

Description

A vulnerability was found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

🔴Vulnerability Details

4
GHSA
request-filtering-agent SSRF Bypass via HTTPS Requests to 127.0.0.12025-08-25
GHSA
GHSA-5prv-pch2-5cpp: A vulnerability was found in code-projects Online Medicine Guide 12025-08-01
CVEList
code-projects Online Medicine Guide login.php sql injection2025-08-01
GHSA
SSRF in sliver teamserver2025-02-19

💥Exploits & PoCs

1
Exploit-DB
FortiWeb 8.0.2 - Remote Code Execution2026-04-08

📋Vendor Advisories

1
Microsoft
Libopensc: heap buffer overflow in openpgp driver when generating key2024-09-10
CVE-2025-8443 — Injection in Online Medicine Guide | cvebase