CVE-2025-3211
published 2025-04-04CVE-2025-3211: A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.40%
33.0th percentile
A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /birthing_print.php. The manipulation of the argument itr_no/birth_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code-projects | patient_record_management_system | — | — |
| fabianros | patient_record_management_system | — | — |
| msrc | azl3_cloud-hypervisor_41.0.139-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_edk2_20240524git3e722403cd16-9_on_azure_linux_3.0 | — | — |
| msrc | azl3_openssl_3.3.3-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_qemu_8.2.0-19_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.75.0-22_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.75.0-24_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.90.0-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.90.0-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_cloud-hypervisor-cvm_38.0.72.2-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_openssl_1.1.1k-36_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
cisa5.4MEDIUM
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9gmr-vw8q-4xjq: A vulnerability classified as critical has been found in code-projects Patient Record Management System 1
ghsa_unreviewed·2025-04-04
CVE-2025-3211 [MEDIUM] CWE-74 GHSA-9gmr-vw8q-4xjq: A vulnerability classified as critical has been found in code-projects Patient Record Management System 1
A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /birthing_print.php. The manipulation of the argument itr_no leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CISA
OpenPLC ScadaBR Cross-site Scripting Vulnerability
cisa·2025-11-28·CVSS 5.4
CVE-2021-26829 [MEDIUM] CWE-79 OpenPLC ScadaBR Cross-site Scripting Vulnerability
Vulnerability: OpenPLC ScadaBR Cross-site Scripting Vulnerability
Affected: OpenPLC ScadaBR
OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/SCADA-LTS/Scada-LTS/pull/3211 ; https://nvd.nist.gov/vuln/detail/CVE-2021-26829
Remediation Due Date: 2025-12-19
Red Hat
openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
vendor_redhat·2025-09-30·CVSS 7.5
CVE-2025-9230 [HIGH] CWE-787 openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
Issue summary: An application trying to decrypt CMS messages encrypted using
password based encryption can trigger an out-of-bounds read and write.
Impact summary: This out-of-bounds read may trigger a crash which leads to
Denial of Service for an application. The out-of-bounds write can cause
a memory corruption which can have various consequences including
a Denial of Service or Execution of attacker-supplied code.
Although the consequences of a successful exploit of this vulnerability
could be severe, the probability that the attacker would be able to
perform it is low. Besides, password based (PWRI) encryption support in CMS
messages is very rarely used. For that reason the issue was assessed as
Moderate severity according to
Microsoft
Out-of-bounds read & write in RFC 3211 KEK Unwrap
vendor_msrc·2025-09-09·CVSS 7.5
CVE-2025-9230 [HIGH] CWE-125 Out-of-bounds read & write in RFC 3211 KEK Unwrap
Out-of-bounds read & write in RFC 3211 KEK Unwrap
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
openssl: openssl
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.m
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-9230 mingw-openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap [fedora-42]
bugzilla·2025-10-01·CVSS 7.5
CVE-2025-9230 [HIGH] CVE-2025-9230 mingw-openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap [fedora-42]
CVE-2025-9230 mingw-openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all b
Bugzilla
CVE-2025-9230 edk2: Out-of-bounds read & write in RFC 3211 KEK Unwrap [fedora-42]
bugzilla·2025-10-01·CVSS 7.5
CVE-2025-9230 [HIGH] CVE-2025-9230 edk2: Out-of-bounds read & write in RFC 3211 KEK Unwrap [fedora-42]
CVE-2025-9230 edk2: Out-of-bounds read & write in RFC 3211 KEK Unwrap [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug report
2025-04-04
Published