A flaw has been found in code-projects Hospital Management System 1.0. Affected is the function session of the component express-session. This manipulation of the argument secret with the input secret causes use of hard-coded cryptographic key
. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been published and may be used.
Metrics
Affected Vendors & Products
References
History
Sat, 11 Oct 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw has been found in code-projects Hospital Management System 1.0. Affected is the function session of the component express-session. This manipulation of the argument secret with the input secret causes use of hard-coded cryptographic key . The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been published and may be used. | |
Title | code-projects Hospital Management System express-session hard-coded key | |
Weaknesses | CWE-320 CWE-321 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-10-11T17:32:05.833Z
Reserved: 2025-10-10T13:59:43.074Z
Link: CVE-2025-11609

No data.

Status : Received
Published: 2025-10-11T18:15:30.093
Modified: 2025-10-11T18:15:30.093
Link: CVE-2025-11609

No data.

No data.