CVE-2025-5361: Campcodes Online Hospital Management System contact.php sql injection
A vulnerability, which was classified as critical, has been found in Campcodes Online Hospital Management System 1.0. This issue affects some unknown processing of the file /contact.php. The manipulation of the argument fullname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5361?
CVE-2025-5361 is classified as a critical vulnerability.
How does CVE-2025-5361 exploit SQL injection?
CVE-2025-5361 exploits SQL injection through improper handling of the 'fullname' argument in the '/contact.php' file.
What systems are affected by CVE-2025-5361?
CVE-2025-5361 affects the Campcodes Online Hospital Management System version 1.0.
How can I fix the vulnerability CVE-2025-5361?
To fix CVE-2025-5361, sanitize user input and implement prepared statements to prevent SQL injection.
What potential impact does CVE-2025-5361 have on my application?
The potential impact of CVE-2025-5361 includes unauthorized access to the database and potential data breaches.