CVE-2025-3208: code-projects Patient Record Management System xray_print.php sql injection
A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /xrayprint.php. The manipulation of the argument itrno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3208?
CVE-2025-3208 has been classified as critical due to the potential for SQL injection.
How do I fix CVE-2025-3208?
To fix CVE-2025-3208, you should sanitize and validate all user inputs in the itr_no argument to prevent SQL injection.
Which system is affected by CVE-2025-3208?
CVE-2025-3208 affects the Patient Record Management System version 1.0 by code-projects.
Can CVE-2025-3208 be exploited remotely?
Yes, CVE-2025-3208 can be exploited remotely, allowing attackers to manipulate the SQL queries.
What is the specific vulnerability type in CVE-2025-3208?
The specific vulnerability type in CVE-2025-3208 is SQL injection due to improper handling of the itr_no argument.