SQL Injection Vulnerability in Patient Record Management System by Code-Projects
CVE-2025-3685
Key Information:
- Vendor
- Code-projects
- Status
- Patient Record Management System
- Vendor
- CVE Published:
- 16 April 2025
Badges
Summary
A critical vulnerability exists in the Patient Record Management System, specifically in the /edit_fpatient.php file, due to improper handling of the ID argument. This oversight allows attackers to manipulate SQL queries, leading to SQL injection. The vulnerability can be exploited remotely, exposing sensitive data and compromising system integrity. Public disclosure of this exploit could encourage malicious activities against affected installations.
Affected Version(s)
Patient Record Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved