Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-63497

Опубликовано: 10 нояб. 2025
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System version 1.0 contains an SQL injection vulnerability. The pat_number GET parameter is directly concatenated into SQL queries without proper sanitization, allowing authenticated attackers (doctor role) to execute arbitrary SQL queries.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rickxy:hospital_management_system:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 10%
0.00034
Низкий

7.1 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.2
github
3 месяца назад

The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System version 1.0 contains an SQL injection vulnerability. The pat_number GET parameter is directly concatenated into SQL queries without proper sanitization, allowing authenticated attackers (doctor role) to execute arbitrary SQL queries.

EPSS

Процентиль: 10%
0.00034
Низкий

7.1 High

CVSS3

Дефекты

CWE-89