CVE-2025-9753: Campcodes Online Hospital Management System Patient Search patient-search.php cross site scripting
A vulnerability was detected in Campcodes Online Hospital Management System 1.0. The affected element is an unknown function of the file /admin/patient-search.php of the component Patient Search Module. Performing manipulation of the argument Search by Name Mobile No results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9753?
CVE-2025-9753 has a critical severity rating due to its potential for unauthorized access and exploitation.
How do I fix CVE-2025-9753?
To fix CVE-2025-9753, you should apply security patches released by Campcodes or implement input validation to the Search by Name Mobile No argument.
What type of vulnerability is CVE-2025-9753?
CVE-2025-9753 is classified as a cross-site scripting (XSS) vulnerability affecting the Patient Search Module.
Which software is affected by CVE-2025-9753?
CVE-2025-9753 affects Campcodes Online Hospital Management System version 1.0.
Can CVE-2025-9753 lead to data breaches?
Yes, CVE-2025-9753 can lead to data breaches if exploited, allowing attackers to manipulate patient information.