CyberRota Analysis
AI-GeneratedA SQL injection vulnerability exists in the /search.php file of the kishan0725 Hospital-Management-System 1.0, allowing remote attackers to manipulate the Contact parameter. This flaw could lead to unauthorized access to sensitive data within the system. Organizations using this software should prioritize remediation efforts due to the high severity and public availability of exploit code.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.