PT-2025-38280 · Itsourcecode · Itsourcecode Online Clinic Management System
Drewbyte
·
Published
2025-09-17
·
Updated
2025-09-18
·
CVE-2025-10620
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
itsourcecode Online Clinic Management System version 1.0
Description
A flaw has been found in the itsourcecode Online Clinic Management System. The vulnerability affects unknown code within the
/editp2.php file. Manipulation of the id, firstname, lastname, type, age, and address arguments can lead to SQL injection. The attack can be executed remotely.Recommendations
As a temporary workaround, consider restricting access to the
/editp2.php file until a patch is available.
Sanitize the id, firstname, lastname, type, age, and address parameters before using them in database queries.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Itsourcecode Online Clinic Management System