Campcodes Online Hospital Management System vulnerabilities
21 known vulnerabilities affecting campcodes/online_hospital_management_system.
Total CVEs
21
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM20
Vulnerabilities
Page 1 of 2
CVE-2025-63719HIGHCVSS 7.3v1.02025-11-19
CVE-2025-63719 [HIGH] CWE-89 CVE-2025-63719: Campcodes Online Hospital Management System 1.0 is vulnerable to SQL Injection in /admin/index.php v
Campcodes Online Hospital Management System 1.0 is vulnerable to SQL Injection in /admin/index.php via the parameter username.
nvd
CVE-2025-9753MEDIUMCVSS 4.8v1.02025-09-01
CVE-2025-9753 [MEDIUM] CWE-79 CVE-2025-9753: A vulnerability was detected in Campcodes Online Hospital Management System 1.0. The affected elemen
A vulnerability was detected in Campcodes Online Hospital Management System 1.0. The affected element is an unknown function of the file /admin/patient-search.php of the component Patient Search Module. Performing manipulation of the argument Search by Name Mobile No results in cross site scripting. The attack may be initiated remotely. The exploit is
cvelistv5nvd
CVE-2025-9754MEDIUMCVSS 5.1v1.02025-09-01
CVE-2025-9754 [MEDIUM] CWE-79 CVE-2025-9754: A flaw has been found in Campcodes Online Hospital Management System 1.0. The impacted element is an
A flaw has been found in Campcodes Online Hospital Management System 1.0. The impacted element is an unknown function of the file /edit-profile.php of the component Edit Profile Page. Executing manipulation of the argument Username can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used.
cvelistv5nvd
CVE-2025-6406MEDIUMCVSS 6.9v1.02025-06-21
CVE-2025-6406 [MEDIUM] CWE-74 CVE-2025-6406: A vulnerability, which was classified as critical, has been found in Campcodes Online Hospital Manag
A vulnerability, which was classified as critical, has been found in Campcodes Online Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/forgot-password.php. The manipulation of the argument fullname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the publ
cvelistv5nvd
CVE-2025-6407MEDIUMCVSS 6.9v1.02025-06-21
CVE-2025-6407 [MEDIUM] CWE-74 CVE-2025-6407: A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management
A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. This affects an unknown part of the file /user-login.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2025-6408MEDIUMCVSS 6.9v1.02025-06-21
CVE-2025-6408 [MEDIUM] CWE-74 CVE-2025-6408: A vulnerability has been found in Campcodes Online Hospital Management System 1.0 and classified as
A vulnerability has been found in Campcodes Online Hospital Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /doctor/search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2025-5603MEDIUMCVSS 6.9v1.02025-06-04
CVE-2025-5603 [MEDIUM] CWE-74 CVE-2025-5603: A vulnerability has been found in Campcodes Hospital Management System 1.0 and classified as critica
A vulnerability has been found in Campcodes Hospital Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument full_name/username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and
nvd
CVE-2025-5604MEDIUMCVSS 6.9v1.02025-06-04
CVE-2025-5604 [MEDIUM] CWE-74 CVE-2025-5604: A vulnerability was found in Campcodes Hospital Management System 1.0 and classified as critical. Af
A vulnerability was found in Campcodes Hospital Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user-login.php. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-5602MEDIUMCVSS 6.9v1.02025-06-04
CVE-2025-5602 [MEDIUM] CWE-74 CVE-2025-5602: A vulnerability, which was classified as critical, was found in Campcodes Hospital Management System
A vulnerability, which was classified as critical, was found in Campcodes Hospital Management System 1.0. Affected is an unknown function of the file /admin/registration.php. The manipulation of the argument full_name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-5365MEDIUMCVSS 6.9v1.02025-05-31
CVE-2025-5365 [MEDIUM] CWE-74 CVE-2025-5365: A vulnerability was found in Campcodes Online Hospital Management System 1.0. It has been classified
A vulnerability was found in Campcodes Online Hospital Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/patient-search.php. The manipulation of the argument searchdata leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be
cvelistv5nvd
CVE-2025-5362MEDIUMCVSS 6.9v1.02025-05-30
CVE-2025-5362 [MEDIUM] CWE-74 CVE-2025-5362: A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management
A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/doctor-specilization.php. The manipulation of the argument doctorspecilization leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the pub
cvelistv5nvd
CVE-2025-5361MEDIUMCVSS 6.9v1.02025-05-30
CVE-2025-5361 [MEDIUM] CWE-74 CVE-2025-5361: A vulnerability, which was classified as critical, has been found in Campcodes Online Hospital Manag
A vulnerability, which was classified as critical, has been found in Campcodes Online Hospital Management System 1.0. This issue affects some unknown processing of the file /contact.php. The manipulation of the argument fullname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2025-5363MEDIUMCVSS 6.9v1.02025-05-30
CVE-2025-5363 [MEDIUM] CWE-74 CVE-2025-5363: A vulnerability has been found in Campcodes Online Hospital Management System 1.0 and classified as
A vulnerability has been found in Campcodes Online Hospital Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /doctor/index.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may
cvelistv5nvd
CVE-2025-5364MEDIUMCVSS 6.9v1.02025-05-30
CVE-2025-5364 [MEDIUM] CWE-74 CVE-2025-5364: A vulnerability was found in Campcodes Online Hospital Management System 1.0 and classified as criti
A vulnerability was found in Campcodes Online Hospital Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /doctor/add-patient.php. The manipulation of the argument patname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be u
cvelistv5nvd
CVE-2025-5360MEDIUMCVSS 6.9v1.02025-05-30
CVE-2025-5360 [MEDIUM] CWE-74 CVE-2025-5360: A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0.
A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability affects unknown code of the file /book-appointment.php. The manipulation of the argument doctor leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2025-5359MEDIUMCVSS 6.9v1.02025-05-30
CVE-2025-5359 [MEDIUM] CWE-74 CVE-2025-5359: A vulnerability classified as critical has been found in Campcodes Online Hospital Management System
A vulnerability classified as critical has been found in Campcodes Online Hospital Management System 1.0. This affects an unknown part of the file /appointment-history.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2025-5298MEDIUMCVSS 6.9PoCv1.02025-05-28
CVE-2025-5298 [MEDIUM] CWE-74 CVE-2025-5298: A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management
A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/betweendates-detailsreports.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the
cvelistv5nvd
CVE-2025-5246MEDIUMCVSS 6.9v1.02025-05-27
CVE-2025-5246 [MEDIUM] CWE-74 CVE-2025-5246: A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0.
A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability affects unknown code of the file /hms/admin/query-details.php. The manipulation of the argument adminremark leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2025-5229MEDIUMCVSS 6.9v1.02025-05-27
CVE-2025-5229 [MEDIUM] CWE-74 CVE-2025-5229: A vulnerability was found in Campcodes Online Hospital Management System 1.0. It has been rated as c
A vulnerability was found in Campcodes Online Hospital Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/view-patient.php. The manipulation of the argument viewid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may b
cvelistv5nvd
CVE-2025-5224MEDIUMCVSS 6.9v1.02025-05-27
CVE-2025-5224 [MEDIUM] CWE-74 CVE-2025-5224: A vulnerability classified as critical has been found in Campcodes Online Hospital Management System
A vulnerability classified as critical has been found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/add-doctor.php. The manipulation of the argument Doctorspecialization leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be u
cvelistv5nvd
1 / 2Next →