CVE-2025-2664

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 23, 2025
CWE ID 23
CWE ID 284

Summary

CVE-2025-2664 is a critical vulnerability affecting CodeZips Hospital Management System 1.0. This issue lies within an unspecified feature of the file /suadpeted.php, making it vulnerable to SQL injection attacks. An attacker can exploit this remotely by manipulating the ID argument. The potential consequences of this vulnerability are significant, as the exploit has already been disclosed to the public, increasing the risk of widespread exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share