SQL Injection Vulnerability in Le-show Medical Practice Management System by Le-yan
CVE-2025-3708
9.8CRITICAL
What is CVE-2025-3708?
The Le-show medical practice management system from Le-yan is susceptible to an SQL Injection vulnerability, which enables unauthenticated remote attackers to execute arbitrary SQL commands. This exploitation can lead to unauthorized access, allowing attackers to read, modify, and delete sensitive database contents, posing significant risks to patient data integrity and confidentiality.
Affected Version(s)
Le-show 0 <= 3.2.25
