CVE-2025-11609
11.10.2025, 18:15
A flaw has been found in code-projects Hospital Management System 1.0. Affected is the function session of the component express-session. This manipulation of the argument secret with the input secret causes use of hard-coded cryptographic key . The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been published and may be used.Enginsight
| Vendor | Product | Version |
|---|---|---|
| fabian | hospital_management_system | 1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References