CVE-2025-9028
CRITICALCVSS 9.8/10EPSS 0.39%
Last modified
CVE-2025-9028 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A flaw has been found in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of the file /adphar.php. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
A flaw has been found in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of the file /adphar.php. Executing manipulation of the argument phuname can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Anisha | Online Medicine Guide | 1.0 |
References
- https://code-projects.org/Product
- https://github.com/Jackie1732/CVE/issues/3Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.320093Permissions Required, VDB Entry
- https://vuldb.com/?id.320093Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.630188Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-9028?
A flaw has been found in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of the file /adphar.php. Executing manipulation of the argument phuname can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
How severe is CVE-2025-9028?
CVE-2025-9028 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.39% probability of exploitation in the next 30 days.
How do I fix CVE-2025-9028?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-9022A vulnerability was identified in SourceCodester Online Bank…9.8
- CVE-2025-9023A vulnerability has been found in Tenda AC7 and AC18 15.03.0…8.8
- CVE-2025-9024A vulnerability was found in PHPGurukul Beauty Parlour Manag…9.8
- CVE-2025-9025A vulnerability was determined in code-projects Simple Cafe …8.8
- CVE-2025-9026A vulnerability was identified in D-Link DIR-860L 2.04.B04. …9.8
- CVE-2025-9027A vulnerability has been found in code-projects Online Medic…9.8
- CVE-2025-9029The WDesignKit – Elementor & Gutenberg Starter Templates, Pa…4.3
- CVE-2025-9030The Majestic Before After Image plugin for WordPress is vuln…5.4
- CVE-2025-9031Observable Timing Discrepancy vulnerability in DivvyDrive In…4.3
- CVE-2025-9032Heap buffer out-of-bounds read vulnerability in Avira Antivi…7.8
- CVE-2025-9033Heap buffer out-of-bounds read vulnerability in Avira Antivi…7.8
- CVE-2025-9034The Wp Edit Password Protected WordPress plugin before 1.3.…6.1
Are you affected by CVE-2025-9028?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
