SQL Injection Vulnerability in Hospital Management System by Kishan0725
CVE-2023-40992

6.5MEDIUM

Key Information:

Vendor

Kishan0725

Vendor
CVE Published:
7 August 2025

What is CVE-2023-40992?

The Hospital Management System 4, developed by Kishan0725, is susceptible to a SQL injection attack through the 'password2' parameter in the func.php file. This vulnerability could allow malicious actors to manipulate database queries, potentially leading to unauthorized access to sensitive information. It emphasizes the importance of input validation and secure coding practices to protect user data in web applications.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.