CVE-2025-7147: CodeAstro Patient Record Management System login.php sql injection
A vulnerability has been found in CodeAstro Patient Record Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7147?
CVE-2025-7147 is classified as a critical vulnerability affecting the CodeAstro Patient Record Management System.
How does the CVE-2025-7147 vulnerability occur?
CVE-2025-7147 occurs due to SQL injection vulnerabilities in the /login.php file when the uname argument is manipulated.
What software is affected by CVE-2025-7147?
CVE-2025-7147 affects CodeAstro Patient Record Management System version 1.0.
How can I fix CVE-2025-7147?
To fix CVE-2025-7147, implement prepared statements and parameterized queries to prevent SQL injection in input handling.
What are the potential impacts of CVE-2025-7147?
The potential impacts of CVE-2025-7147 include unauthorized access to sensitive patient data and system compromise.