PT-2025-46180 · Unknown · Rickxy Hospital Management System

Published

2025-11-10

·

Updated

2025-12-11

·

CVE-2025-63497

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions rickxy Hospital Management System version 1.0
Description The patient prescription viewing functionality within the his doc view single patient.php component contains an SQL injection issue. The pat number GET parameter is directly incorporated into SQL queries without sufficient sanitization. This allows authenticated attackers with the doctor role to execute arbitrary SQL queries. The vulnerable parameter is pat number.
Recommendations Apply proper sanitization to the pat number GET parameter before using it in SQL queries.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-63497

Affected Products

Rickxy Hospital Management System