PT-2025-38280 · Itsourcecode · Itsourcecode Online Clinic Management System

Drewbyte

·

Published

2025-09-17

·

Updated

2025-09-18

·

CVE-2025-10620

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions itsourcecode Online Clinic Management System version 1.0
Description A flaw has been found in the itsourcecode Online Clinic Management System. The vulnerability affects unknown code within the /editp2.php file. Manipulation of the id, firstname, lastname, type, age, and address arguments can lead to SQL injection. The attack can be executed remotely.
Recommendations As a temporary workaround, consider restricting access to the /editp2.php file until a patch is available. Sanitize the id, firstname, lastname, type, age, and address parameters before using them in database queries.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-10620

Affected Products

Itsourcecode Online Clinic Management System