PT-2025-20623 · Unknown · Code-Projects Hospital Management System

·

CVE-2025-4499

·

Published

2025-05-10

·

Updated

2025-05-10

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Simple Hospital Management System version 1.0
Description A critical vulnerability was found in the Simple Hospital Management System. The issue affects the Add function of the Add Information component. Manipulation of the x[i].name and x[i].disease arguments leads to a stack-based buffer overflow. This attack must be approached locally, and the exploit has been disclosed to the public.
Recommendations For code-projects Simple Hospital Management System version 1.0, consider disabling the Add function of the Add Information component until a patch is available to prevent exploitation of the buffer overflow vulnerability. Restrict access to the Add Information component to minimize the risk of exploitation. Avoid using the x[i].name and x[i].disease arguments in the affected function until the issue is resolved.

Exploit

Fix

Buffer Overflow

Stack Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-4499

Affected Products

Code-Projects Hospital Management System