PT-2025-20623 · Unknown · Code-Projects Hospital Management System
Zzzxc
·
Published
2025-05-10
·
Updated
2025-05-10
·
CVE-2025-4499
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
code-projects Simple Hospital Management System version 1.0
Description
A critical vulnerability was found in the Simple Hospital Management System. The issue affects the
Add function of the Add Information component. Manipulation of the x[i].name and x[i].disease arguments leads to a stack-based buffer overflow. This attack must be approached locally, and the exploit has been disclosed to the public.Recommendations
For code-projects Simple Hospital Management System version 1.0, consider disabling the
Add function of the Add Information component until a patch is available to prevent exploitation of the buffer overflow vulnerability. Restrict access to the Add Information component to minimize the risk of exploitation. Avoid using the x[i].name and x[i].disease arguments in the affected function until the issue is resolved.Exploit
Fix
Buffer Overflow
Stack Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Code-Projects Hospital Management System