CVE-2025-3186

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 4, 2025
Updated: Apr 15, 2025
CWE ID 74
CWE ID 89

Summary

CVE-2025-3186 is a critical vulnerability affecting the Projectworlds Online Doctor Appointment Booking System 1.0. This issue lies in an unidentified functionality of the file /patient/invoice.php, which is susceptible to SQL injection. The manipulation of the appid argument enables remote attackers to exploit this vulnerability. Public disclosure of the exploit increases the risk of this vulnerability being exploited in real-world scenarios.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share