SQL Injection Vulnerability in Campcodes Online Hospital Management System 1.0
CVE-2025-5363
What is CVE-2025-5363?
A vulnerability in Campcodes Online Hospital Management System version 1.0 has been identified, specifically in the /doctor/index.php file. This issue involves improper handling of the Username argument, allowing attackers to execute SQL injection attacks remotely. The publicly disclosed exploit poses a significant risk, as it can be utilized by malicious actors to access sensitive data or manipulate the database systems. Users and administrators should take immediate action to mitigate this vulnerability by applying necessary security measures.
Affected Version(s)
Online Hospital Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved