SQL Injection Vulnerability in Hospital Management System 4.0
CVE-2025-69949

7.3HIGH

Key Information:

Vendor

kishan0725

Vendor
CVE Published:
29 July 2026

What is CVE-2025-69949?

The Hospital Management System 4.0 by kishan0725 is exposed to a significant SQL Injection vulnerability through the check_availability.php script. This flaw allows unauthorized users to manipulate SQL queries by exploiting the emailid and email parameters, potentially leading to unauthorized access to sensitive data and affecting overall system integrity.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.