CVE-2025-2664
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Mar 23, 2025
CWE ID 23
CWE ID 284
Summary
CVE-2025-2664 is a critical vulnerability affecting CodeZips Hospital Management System 1.0. This issue lies within an unspecified feature of the file /suadpeted.php, making it vulnerable to SQL injection attacks. An attacker can exploit this remotely by manipulating the ID argument. The potential consequences of this vulnerability are significant, as the exploit has already been disclosed to the public, increasing the risk of widespread exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.