First published: Mon Apr 28 2025(Updated: )
A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file /edit_spatient.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Patient Record Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4021 has been classified as critical due to its potential for remote SQL injection.
CVE-2025-4021 affects the /edit_spatient.php file, allowing manipulation of the ID argument for SQL injection attacks.
Exploiting CVE-2025-4021 could allow attackers to access or manipulate sensitive data within the Patient Record Management System.
To protect against CVE-2025-4021, implement input validation and prepare statements to prevent SQL injection vulnerabilities.
As of now, there is no specific patch disclosed for CVE-2025-4021, so it's recommended to monitor updates from the vendor.