CVE-2025-3708: Le-show Medical Practice Management System - SQL Injection
Published May 2, 2025
·Updated
Le-show medical practice management system from Le-yan has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Affected Software
2 affected components
Le-yan Medical Practice Management System
Le-show Le-yan<=3.2.25
Remediation
Information
Update to version V3.0.30 or later
Event History
May 2, 2025
CVE Published
via MITRE·02:55 AM
Data Sourced
via MITRE·02:55 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-3708?
CVE-2025-3708 has a high severity rating due to its potential for unauthorized data manipulation.
2
How do I fix CVE-2025-3708?
To fix CVE-2025-3708, ensure that parameterized queries are used to prevent SQL injection and update to the latest version of the Le-yan Medical Practice Management System.
3
What systems are affected by CVE-2025-3708?
CVE-2025-3708 affects the Le-yan Medical Practice Management System.
4
What types of attacks can CVE-2025-3708 enable?
CVE-2025-3708 can enable attackers to read, modify, and delete database contents.
5
Who can exploit CVE-2025-3708?
CVE-2025-3708 can be exploited by unauthenticated remote attackers.