CVE-2025-3303: code-projects Patient Record Management System birthing_record.php sql injection
A vulnerability, which was classified as critical, has been found in code-projects Patient Record Management System 1.0. Affected by this issue is some unknown functionality of the file /birthingrecord.php. The manipulation of the argument itrno leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3303?
CVE-2025-3303 is classified as a critical vulnerability.
How does CVE-2025-3303 impact Patient Record Management System?
CVE-2025-3303 affects the functionality of the file /birthing_record.php, allowing for SQL injection through the parameter itr_no.
How do I fix CVE-2025-3303?
To fix CVE-2025-3303, it is recommended to sanitize and validate user inputs for the itr_no parameter to prevent SQL injection.
What type of vulnerability is CVE-2025-3303?
CVE-2025-3303 is identified as an SQL injection vulnerability.
Which software is affected by CVE-2025-3303?
CVE-2025-3303 affects version 1.0 of the Patient Record Management System developed by code-projects.