CVE-2025-13248: SourceCodester Patients Waiting Area Queue Management System api_patient_schedule.php sql injection
A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element is an unknown function of the file /php/apipatientschedule.php. This manipulation of the argument appointmentID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13248?
The severity of CVE-2025-13248 is rated as high due to the potential for SQL injection vulnerabilities that can compromise sensitive data.
How do I fix CVE-2025-13248?
To fix CVE-2025-13248, sanitize and validate the input to the appointmentID parameter to prevent SQL injection.
Which systems are affected by CVE-2025-13248?
CVE-2025-13248 affects the SourceCodester Patients Waiting Area Queue Management System, specifically version 1.0.
What type of vulnerability is CVE-2025-13248?
CVE-2025-13248 is a SQL injection vulnerability caused by improper handling of the appointmentID argument.
Can CVE-2025-13248 be exploited remotely?
Yes, CVE-2025-13248 can be exploited remotely if an attacker manipulates the appointmentID parameter in the API.