CVE-2025-5779: code-projects Patient Record Management System birthing.php sql injection
A vulnerability has been found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /birthing.php. The manipulation of the argument itrno/compid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5779?
CVE-2025-5779 is classified as a critical vulnerability.
How does CVE-2025-5779 affect the Patient Record Management System?
CVE-2025-5779 allows for SQL injection through the manipulation of the arguments itr_no and comp_id in the /birthing.php file.
How can CVE-2025-5779 be mitigated?
To mitigate CVE-2025-5779, input validation and parameterized queries should be implemented to prevent SQL injection.
Which software versions are affected by CVE-2025-5779?
CVE-2025-5779 affects version 1.0 of the Patient Record Management System developed by code-projects.
What steps should be taken if CVE-2025-5779 is exploited?
If CVE-2025-5779 is exploited, it is crucial to immediately assess the system for unauthorized access and apply security patches.