Cross Site Scripting Vulnerability in code-projects POS Pharmacy System
CVE-2025-9921
Key Information:
- Vendor
Code-projects
- Status
- Vendor
- CVE Published:
- 3 September 2025
Badges
What is CVE-2025-9921?
A vulnerability has been identified in the code-projects POS Pharmacy System version 1.0. It exists due to insufficient validation of user-supplied inputs in the file /main/products.php. This flaw allows attackers to inject malicious scripts through manipulated arguments such as product_code, gen_name, product_name, and supplier. The impact can lead to unauthorized actions executed on behalf of users or the exposure of sensitive data. As the exploit is publicly available, organizations using this version should take immediate action to secure their systems.
Affected Version(s)
POS Pharmacy System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved