CVE-2025-5208Injection in Online Hospital Management System

Severity
6.9MEDIUMNVD
EPSS
0.2%
top 56.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 26
Latest updateMay 27

Description

A vulnerability, which was classified as critical, was found in SourceCodester Online Hospital Management System 1.0. This affects an unknown part of the file /admin/check_availability.php. The manipulation of the argument emailid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

🔴Vulnerability Details

2
GHSA
GHSA-jxcf-8cjj-rm75: A vulnerability, which was classified as critical, was found in SourceCodester Online Hospital Management System 12025-05-27
CVEList
SourceCodester Online Hospital Management System check_availability.php sql injection2025-05-26

📋Vendor Advisories

1
Microsoft
remote code execution vulnerability in ipmitool2020-02-11
CVE-2025-5208 — Injection | cvebase