What is CVE-2025-69949?
Kishan0725 Hospital Management System 4.0 contains an SQL Injection vulnerability in the 'check_availability.php' file via the 'emailid' and 'email' parameters. This flaw could allow attackers to send unauthorized queries to the database. To prevent potential data leakage, input sanitization and parameterized queries should be implemented.
Azərbaycanca: Kishan0725 Hospital Management System 4.0 proqramında 'check_availability.php' faylında 'emailid' və 'email' parametrləri vasitəsilə SQL Injection zəifliyi aşkarlanıb. Bu, təcavüzkara verilənlər bazasına icazəsiz sorğular göndərməyə imkan verir. Mümkün məlumat sızmasının qarşısını almaq üçün daxil olan verilənlərin təmizlənməsi və parametrləşdirilmiş sorğulardan istifadə edilməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: kishan0725
FAQ2
Where is the SQL Injection vulnerability located in Kishan0725 Hospital Management System 4.0?
The vulnerability exists in the 'check_availability.php' file via the 'emailid' and 'email' parameters.
What measures should be taken to mitigate this SQL Injection vulnerability?
Input sanitization and the use of parameterized queries should be implemented.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.