What is CVE-2025-69944?
kishan0725 Hospital Management System 4.0 has an SQL Injection vulnerability in the view-medhistory.php endpoint via the viewid parameter. This could allow attackers to manipulate database queries, potentially exposing sensitive data. It is recommended to restrict access to the affected endpoint until a security patch is applied.
Azərbaycanca: kishan0725 Hospital Management System 4.0 proqramının view-medhistory.php faylındakı `viewid` parametri SQL Injection zəifliyinə məruz qalıb. Bu, təcavüzkara verilənlər bazasına icazəsiz sorğular göndərməyə imkan verir. Təhlükəsizlik patchi tətbiq olunana qədər həmin endpoint-ə giriş məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: kishan0725
FAQ2
Which file in kishan0725 Hospital Management System 4.0 contains an SQL Injection vulnerability?
The SQL Injection vulnerability exists in the view-medhistory.php file via the viewid parameter.
What mitigation is recommended until a security patch is available?
It is recommended to restrict access to the affected endpoint until a security patch is applied.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.