SQL Injection Vulnerability in Hospital Management System by Kishan0725
CVE-2023-41532

8.8HIGH

Key Information:

Vendor

Kishan0725

Vendor
CVE Published:
7 August 2025

What is CVE-2023-41532?

A SQL injection vulnerability exists in the Hospital Management System v4, specifically through the doctor_contact parameter in doctorsearch.php. This flaw allows attackers to execute arbitrary SQL queries, potentially compromising sensitive information stored in the database. Exploitation of this vulnerability poses significant risks to data confidentiality and integrity, making it crucial for users to implement appropriate security measures.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.