A SQL Injection vulnerability exists in the kishan0725 Hospital Management System 4.0 within the /doctor/edit-patient.php?editid=1 endpoint. This issue allows attackers to inject malicious SQL code, potentially leading to unauthorized access or manipulation of sensitive data. The vulnerability has a CVSS score of 7.3 and a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L. Defenders should asses [truncated]
The CVE-2025-69942 vulnerability in kishan0725 Hospital Management System 4.0 allows for SQL Injection in the /hms/doctor/view-patient.php?viewid=1 endpoint. This critical vulnerability has a CVSS score of 9.8 and could potentially allow attackers to manipulate patient data or disrupt hospital operations. The vulnerability is a result of inadequate input validation and sanitization in the view-patient.php [truncated]