CVE-2025-6407: Campcodes Online Hospital Management System user-login.php sql injection
A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. This affects an unknown part of the file /user-login.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6407?
CVE-2025-6407 is classified as a critical vulnerability.
How do I fix CVE-2025-6407?
To fix CVE-2025-6407, sanitize and validate user input in the /user-login.php file to prevent SQL injection.
What systems are affected by CVE-2025-6407?
CVE-2025-6407 affects Campcodes Online Hospital Management System version 1.0.
Can CVE-2025-6407 be exploited remotely?
Yes, CVE-2025-6407 can be exploited remotely due to its SQL injection nature.
What type of attack can CVE-2025-6407 facilitate?
CVE-2025-6407 can facilitate SQL injection attacks through manipulation of the Username parameter.