SQL Injection Vulnerability in Campcodes Online Hospital Management System
CVE-2025-5365
7.3HIGH
What is CVE-2025-5365?
A significant SQL injection vulnerability exists in the Campcodes Online Hospital Management System, specifically within the /admin/patient-search.php file. This issue is caused by inadequate validation of the 'searchdata' argument, allowing remote attackers to manipulate database queries. Given that the exploit has been publicly disclosed, it poses a considerable risk to affected systems that have not yet applied mitigating controls.