SQL Injection Vulnerability in Campcodes Online Hospital Management System
CVE-2025-5365

7.3HIGH

Key Information:

Vendor

Campcodes

Vendor
CVE Published:
31 May 2025

What is CVE-2025-5365?

A significant SQL injection vulnerability exists in the Campcodes Online Hospital Management System, specifically within the /admin/patient-search.php file. This issue is caused by inadequate validation of the 'searchdata' argument, allowing remote attackers to manipulate database queries. Given that the exploit has been publicly disclosed, it poses a considerable risk to affected systems that have not yet applied mitigating controls.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2025-5365 : SQL Injection Vulnerability in Campcodes Online Hospital Management System