CVE-2025-5364: Campcodes Online Hospital Management System add-patient.php sql injection
A vulnerability was found in Campcodes Online Hospital Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /doctor/add-patient.php. The manipulation of the argument patname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5364?
CVE-2025-5364 is classified as a critical vulnerability.
What type of vulnerability is CVE-2025-5364?
CVE-2025-5364 is an SQL injection vulnerability affecting Campcodes Online Hospital Management System.
Which file is vulnerable in CVE-2025-5364?
The file vulnerable in CVE-2025-5364 is /doctor/add-patient.php.
How can I mitigate the risks of CVE-2025-5364?
To mitigate CVE-2025-5364, ensure proper input validation and use prepared statements to prevent SQL injection.
Which software versions are affected by CVE-2025-5364?
CVE-2025-5364 affects the Campcodes Online Hospital Management System version 1.0.