CVE-2025-63497: Rickxy Hospital Management System
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System version 1.0 contains an SQL injection vulnerability. The pat_number GET parameter is directly concatenated into SQL queries without proper sanitization, allowing authenticated attackers (doctor role) to execute arbitrary SQL queries.
Affected products
- Rickxy Hospital Management System: version 1.0 only
Published 2025-11-10. Last modified 2026-06-17.