A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file ShiroConfig.java. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Tue, 10 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Jameszbl
Jameszbl db-hospital-drug
CPEs cpe:2.3:a:jameszbl:db-hospital-drug:1.0:*:*:*:*:*:*:*
Vendors & Products Jameszbl
Jameszbl db-hospital-drug

Mon, 14 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file ShiroConfig.java. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title JamesZBL/code-projects db-hospital-drug ShiroConfig.java improper authorization
Weaknesses CWE-266
CWE-285
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-04-14T18:06:22.155Z

Reserved: 2025-04-13T23:36:54.228Z

Link: CVE-2025-3569

cve-icon Vulnrichment

Updated: 2025-04-14T14:11:32.124Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-14T14:15:25.813

Modified: 2026-02-10T21:12:05.753

Link: CVE-2025-3569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.