CVE-2025-4891
Last modified
CVE-2025-4891 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A vulnerability was found in code-projects Police Station Management System 1.0. It has been classified as critical. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
A vulnerability was found in code-projects Police Station Management System 1.0. It has been classified as critical. Affected is the function criminal::display of the file source.cpp of the component Display Record. The manipulation of the argument N leads to buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Code-Projects | Police Station Management System | 1.0 |
References
- https://code-projects.org/Product
- https://github.com/zzzxc643/cve/blob/main/Police-StationManagementSystem.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.309444Permissions Required, VDB Entry
- https://vuldb.com/?id.309444Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.577500Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-4891?
How severe is CVE-2025-4891?
How do I fix CVE-2025-4891?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-48904Vulnerability that cards can call unauthorized APIs in the F…6.2
- CVE-2025-48905Wasm exception capture vulnerability in the arkweb v8 module…8.1
- CVE-2025-48906Authentication bypass vulnerability in the DSoftBus module I…8.8
- CVE-2025-48907Deserialization vulnerability in the IPC module Impact: Succ…6.2
- CVE-2025-48908Ability Auto Startup service vulnerability in the foundation…6.7
- CVE-2025-48909Bypass vulnerability in the device management channel Impact…7.1
- CVE-2025-48910Buffer overflow vulnerability in the DFile module Impact: Su…5.5
- CVE-2025-48911Vulnerability of improper permission assignment in the note …8.2
- CVE-2025-48912An authenticated malicious actor using specially crafted req…6.5
- CVE-2025-48913If untrusted users are allowed to configure JMS for Apache C…9.8
- CVE-2025-48914Improper Neutralization of Input During Web Page Generation …8.6
- CVE-2025-48915Improper Neutralization of Input During Web Page Generation …8.6
Are you affected by CVE-2025-4891?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
