CVE-2025-3685

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Apr 16, 2025
CWE ID 89
CWE ID 74

Summary

CVE-2025-3685 is a newly identified critical vulnerability that impacts the code-projects Patient Record Management System version 1.0. This issue affects an unspecified function in the file /edit_fpatient.php, allowing an attacker to execute SQL injection attacks. The manipulation of the ID argument can be exploited remotely, increasing the threat level. The exploit for this vulnerability has been made public, increasing the risk of potential attacks. It is crucial that users of this Patient Record Management System upgrade to a secure version as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share