CVE-2025-3347: code-projects Patient Record Management System dental_pending.php sql injection
Published Apr 7, 2025
·Updated
A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /dentalpending.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Code-projects Patient Record Management System
Code-projects Patient Record Management System=1.0
Event History
Apr 7, 2025
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-3347?
CVE-2025-3347 is classified as a critical vulnerability.
2
How does CVE-2025-3347 affect Patient Record Management System?
CVE-2025-3347 allows for SQL injection through the manipulation of the argument ID in the file /dental_pending.php.
3
Can CVE-2025-3347 be exploited remotely?
Yes, CVE-2025-3347 is exploitable remotely.
4
What steps should be taken to fix CVE-2025-3347?
To fix CVE-2025-3347, sanitize and validate all user inputs to prevent SQL injection.
5
Which software versions are affected by CVE-2025-3347?
CVE-2025-3347 affects version 1.0 of the Patient Record Management System by code-projects.