PT-2025-40010 · Unknown · Karthikg1908 Hospital Management System

Ischyr

·

Published

2025-09-30

·

Updated

2025-12-23

·

CVE-2025-57254

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Karthikg1908 Hospital Management System (HMS) version 1.0
Description An SQL injection issue exists in the user-login.php and index.php files. The application does not properly sanitize input before using it in SQL queries. This allows remote attackers to execute arbitrary SQL queries through the username and password POST parameters. Successful exploitation could lead to unauthorized access, privilege escalation, account takeover, or exposure of sensitive medical data.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

LPE

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-57254

Affected Products

Karthikg1908 Hospital Management System