PT-2025-14851 · Code Projects · Code-Projects Patient Record Management System

No-Passion

·

Published

2025-04-04

·

Updated

2025-04-04

·

CVE-2025-3211

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions code-projects Patient Record Management System version 1.0
Description A critical issue has been discovered in the /birthing print.php file, where manipulation of the itr no argument leads to SQL injection. This issue can be exploited remotely. The exploit has been publicly disclosed and may be utilized.
Recommendations For code-projects Patient Record Management System version 1.0, consider disabling access to the /birthing print.php file or restricting the use of the itr no argument until a patch is available. Avoid using the itr no argument in the affected file to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-3211

Affected Products

Code-Projects Patient Record Management System