SQL Injection Vulnerability in kishan0725 Hospital Management System
CVE-2025-69945

7.3HIGH

Key Information:

Vendor

kishan0725

Vendor
CVE Published:
29 July 2026

What is CVE-2025-69945?

The kishan0725 Hospital Management System 4.0 is susceptible to an SQL Injection vulnerability found in the edit patient functionality. Specifically, unauthenticated users can manipulate the input parameters within the URL, allowing unauthorized access and potential modification of database records. This vulnerability can lead to serious data integrity issues and unauthorized data exposure.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.