CVE-2025-63497: Rickxy Hospital Management System

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System version 1.0 contains an SQL injection vulnerability. The pat_number GET parameter is directly concatenated into SQL queries without proper sanitization, allowing authenticated attackers (doctor role) to execute arbitrary SQL queries.

Affected products

  • Rickxy Hospital Management System: version 1.0 only

Published 2025-11-10. Last modified 2026-06-17.