CVE-2025-11038

⚪ Do wiadomości

Wstrzyknięcie SQL w Online Clinic Management System umożliwia zdalne ataki.

CVSS
6.3
EPSS
0.3%
Exploit
none
Vendor
angeljudesuarez
Opis źródłowy (NVD)

A weakness has been identified in itsourcecode Online Clinic Management System 1.0. Affected is an unknown function of the file /details.php?action=post. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be exploited.

sql-injection Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2025-09-26 20:15:35 UTC
Ostatnia modyfikacja (NVD)2026-10-09 10:10:00 UTC
Referencje