Junglewise Threat Intelligence

CVE-2025-69944: kishan0725 Hospital Management System SQL injection in view-medhistory.php

CVE-2025-69944 · Severity: info · CVSS 7.5 · Published 2026-07-29

Technologies: Kishan0725 Hospital Management System.

Executive brief

The kishan0725 Hospital Management System, a software platform used to manage patient records and medical history, contains a security flaw that allows unauthorized access to its database. By sending a specially crafted web request, an attacker can bypass security controls to view sensitive medical information. This could lead to a significant breach of patient privacy and regulatory non-compliance.

Technical details

A SQL injection vulnerability exists in kishan0725 Hospital Management System 4.0 within the 'view-medhistory.php' component. The application fails to properly sanitize the 'viewid' GET parameter before using it in a database query. An unauthenticated remote attacker can exploit this by submitting malicious SQL commands, potentially allowing them to extract sensitive data from the hospital's database. The vulnerability was identified via automated taint analysis (TaintRadar). As of the advisory date, no official patch has been confirmed.

Affected products

  • kishan0725 Hospital Management System 4.0

Timeline

  • 2026-07-29: disclosed: CVE published to NVD dataset

References