PT-2025-40846 · Unknown · Hospital-Management-System-Website
Mahushuai
·
Published
2025-10-06
·
Updated
2025-10-06
·
CVE-2025-11319
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
nahiduddinahammed Hospital-Management-System-Website versions prior to e6562429e14b2f88bd2139cae16e87b965024097
Description
A SQL injection issue exists in the /delete.php file processing of the
ai argument. This manipulation can be initiated remotely. The exploit is publicly available. The product uses a rolling release model, and the vendor did not respond to early disclosure attempts.Recommendations
Update to a version prior to e6562429e14b2f88bd2139cae16e87b965024097.
Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hospital-Management-System-Website