CVE-2025-5224: Campcodes Online Hospital Management System add-doctor.php sql injection
Published May 27, 2025
·Updated
A vulnerability classified as critical has been found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/add-doctor.php. The manipulation of the argument Doctorspecialization leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Campcodes Online Hospital Management System
Campcodes Online Hospital Management System=1.0
Event History
May 27, 2025
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
DescriptionSeverityWeakness
Jun 23, 57411
Event
via FIRST·06:10 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-5224?
CVE-2025-5224 is classified as a critical vulnerability.
2
How do I fix CVE-2025-5224?
To fix CVE-2025-5224, sanitize user inputs in the /admin/add-doctor.php file to prevent SQL injection.
3
What type of vulnerability is CVE-2025-5224?
CVE-2025-5224 is a SQL injection vulnerability.
4
Which system is affected by CVE-2025-5224?
CVE-2025-5224 affects the Campcodes Online Hospital Management System 1.0.
5
What is exploited in CVE-2025-5224?
CVE-2025-5224 is exploited through the manipulation of the Doctorspecialization argument.