CVE-2025-5857: code-projects Patient Record Management System urinalysis_record.php sql injection
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /urinalysisrecord.php. The manipulation of the argument itrno leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5857?
CVE-2025-5857 is classified as a critical vulnerability.
How does CVE-2025-5857 affect Patient Record Management System 1.0?
CVE-2025-5857 affects the file /urinalysis_record.php, enabling SQL injection through improper handling of the itr_no argument.
Who is affected by CVE-2025-5857?
CVE-2025-5857 affects users of the Patient Record Management System version 1.0 developed by Fabianros.
How do I fix CVE-2025-5857?
To fix CVE-2025-5857, sanitize all user inputs, especially the itr_no argument, to prevent SQL injection.
What kind of attack can be performed using CVE-2025-5857?
An attacker may initiate a remote SQL injection attack using the vulnerability found in CVE-2025-5857.