CVE-2025-5674: code-projects Patient Record Management System urinalysis_form.php sql injection
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file urinalysisform.php. The manipulation of the argument urinalysisid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5674?
CVE-2025-5674 is classified as critical due to its potential for SQL injection vulnerabilities.
How do I fix CVE-2025-5674?
To fix CVE-2025-5674, sanitize user inputs to prevent SQL injection through the urinalysis_id argument.
What software is affected by CVE-2025-5674?
CVE-2025-5674 affects the Patient Record Management System by code-projects, version 1.0.
What type of attack is associated with CVE-2025-5674?
CVE-2025-5674 is associated with SQL injection attacks that could manipulate database queries.
Is there a way to exploit CVE-2025-5674?
Yes, an attacker could exploit CVE-2025-5674 by manipulating the urinalysis_id argument to execute arbitrary SQL commands.