PT-2025-20623 · Unknown · Code-Projects Hospital Management System

Zzzxc

·

Published

2025-05-10

·

Updated

2025-05-10

·

CVE-2025-4499

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Simple Hospital Management System version 1.0
Description A critical vulnerability was found in the Simple Hospital Management System. The issue affects the Add function of the Add Information component. Manipulation of the x[i].name and x[i].disease arguments leads to a stack-based buffer overflow. This attack must be approached locally, and the exploit has been disclosed to the public.
Recommendations For code-projects Simple Hospital Management System version 1.0, consider disabling the Add function of the Add Information component until a patch is available to prevent exploitation of the buffer overflow vulnerability. Restrict access to the Add Information component to minimize the risk of exploitation. Avoid using the x[i].name and x[i].disease arguments in the affected function until the issue is resolved.

Exploit

Fix

Buffer Overflow

Stack Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2025-4499

Affected Products

Code-Projects Hospital Management System