Cross Site Scripting Vulnerability in code-projects POS Pharmacy System
CVE-2025-9921

4.8MEDIUM

Key Information:

Vendor
CVE Published:
3 September 2025

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2025-9921?

A vulnerability has been identified in the code-projects POS Pharmacy System version 1.0. It exists due to insufficient validation of user-supplied inputs in the file /main/products.php. This flaw allows attackers to inject malicious scripts through manipulated arguments such as product_code, gen_name, product_name, and supplier. The impact can lead to unauthorized actions executed on behalf of users or the exposure of sensitive data. As the exploit is publicly available, organizations using this version should take immediate action to secure their systems.

Affected Version(s)

POS Pharmacy System 1.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

111ctx (VulDB User)
.
CVE-2025-9921 : Cross Site Scripting Vulnerability in code-projects POS Pharmacy System