CVE-2025-11609
Published
CVSS v3
3.7
LOW
CVSS v2
2.6
LOW
Affected
1
PROJECT
Description
A flaw has been found in code-projects Hospital Management System 1.0. Affected is the function session of the component express-session. This manipulation of the argument secret with the input secret causes use of hard-coded cryptographic key . The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been published and may be used.