SQL Injection Vulnerability in mojoomla Hospital Management System
CVE-2025-39386
9.3CRITICAL
What is CVE-2025-39386?
The mojoomla Hospital Management System is susceptible to SQL Injection due to improper neutralization of special elements in SQL commands. This vulnerability allows attackers to manipulate SQL queries, potentially compromising sensitive data and the integrity of the database. It is crucial for users of versions up to 47.0 to implement appropriate security measures to mitigate this risk.
Affected Version(s)
Hospital Management System <= 47.0(20-11-2023)
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Trương Hữu Phúc / truonghuuphuc (Patchstack Alliance)