CVE-2025-3347

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Apr 7, 2025
CWE ID 89
CWE ID 74

Summary

CVE-2025-3347 is a newly identified critical vulnerability affecting the Patient Record Management System 1.0. This issue lies in the code of the /dental_pending.php file, and the manipulation of the ID argument can lead to SQL injection. The vulnerability can be exploited remotely, meaning attackers don't need to have local access to the system. The exploit for this vulnerability has been disclosed publicly, increasing the risk of potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share