SQL Injection Vulnerability in Code-Projects Patient Record Management System
CVE-2025-3348
Key Information:
- Vendor
- Code-projects
- Vendor
- CVE Published:
- 7 April 2025
Badges
Summary
A SQL injection vulnerability exists in the Code-Projects Patient Record Management System (version 1.0), specifically within the file /edit_dpatient.php. Attackers can manipulate the 'ID' parameter to execute arbitrary SQL commands, potentially leading to unauthorized data access and manipulation. This flaw can be exploited remotely, making it imperative for users to secure their systems against possible attacks. The disclosure of this vulnerability raises concerns, urging immediate action to mitigate potential risks associated with it.
Affected Version(s)
Patient Record Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved