The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System version 1.0 contains an SQL injection vulnerability. The pat_number GET parameter is directly concatenated into SQL queries without proper sanitization, allowing authenticated attackers (doctor role) to execute arbitrary SQL queries.
References
| Link | Resource |
|---|---|
| https://github.com/cristibtz/security-research/blob/main/CVE-2025-63497/report.md | Third Party Advisory |
| https://github.com/cristibtz/security-research/tree/main/rickxy-Hospital-Management-System | Broken Link |
Configurations
History
11 Dec 2025, 23:30
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Rickxy hospital Management System
Rickxy |
|
| CPE | cpe:2.3:a:rickxy:hospital_management_system:1.0:*:*:*:*:*:*:* | |
| References | () https://github.com/cristibtz/security-research/blob/main/CVE-2025-63497/report.md - Third Party Advisory | |
| References | () https://github.com/cristibtz/security-research/tree/main/rickxy-Hospital-Management-System - Broken Link |
24 Nov 2025, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
| Summary |
|
12 Nov 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-89 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.2 |
10 Nov 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-10 17:15
Updated : 2025-12-11 23:30
NVD link : CVE-2025-63497
Mitre link : CVE-2025-63497
CVE.ORG link : CVE-2025-63497
JSON object : View
Products Affected
rickxy
- hospital_management_system
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
