Vulnerability Description
The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System version 1.0 contains an SQL injection vulnerability. The pat_number GET parameter is directly concatenated into SQL queries without proper sanitization, allowing authenticated attackers (doctor role) to execute arbitrary SQL queries.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rickxy | Hospital Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/cristibtz/security-research/blob/main/CVE-2025-63497/report.mThird Party Advisory
- https://github.com/cristibtz/security-research/tree/main/rickxy-Hospital-ManagemBroken Link
FAQ
What is CVE-2025-63497?
CVE-2025-63497 is a vulnerability with a CVSS score of 7.1 (HIGH). The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System version 1.0 contains an SQL injection vulnerability. The pat_number GET parameter...
How severe is CVE-2025-63497?
CVE-2025-63497 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-63497?
Check the references section above for vendor advisories and patch information. Affected products include: Rickxy Hospital Management System.