Junglewise Threat Intelligence

CVE-2025-65340: kishan0725 Hospital Management System SQL injection in betweendates-detailsreports.php

CVE-2025-65340 · Severity: info · Published 2026-07-29

Technologies: Kishan0725 Hospital Management System.

Executive brief

The kishan0725 Hospital Management System, a software platform used for managing medical facility operations, contains a security flaw in its reporting module. An attacker can exploit this vulnerability to gain unauthorized access to the underlying database. This could lead to the theft of sensitive patient records, modification of medical data, or full compromise of the hospital's information system.

Technical details

A SQL injection vulnerability exists in kishan0725 Hospital Management System 4.0 within the 'betweendates-detailsreports.php' script. The vulnerability is specifically located in the 'fromdate' parameter, which fails to properly sanitize user-supplied input before using it in a database query. A remote attacker can exploit this by sending specially crafted HTTP requests to the affected endpoint. Successful exploitation allows for unauthorized database enumeration, data extraction, and potentially administrative access to the application. The issue was identified via automated taint analysis and confirmed with SQLmap techniques.

Affected products

  • kishan0725 Hospital Management System 4.0

Timeline

  • 2026-07-29: disclosed: Initial NVD publication date
  • 2026-07-29: advisory: CVE-2025-65340 published

References