Code-Projects Patient Record Management System SQL Injection Vulnerability in Xray Print.php

Vulnerability

A critical SQL injection vulnerability has been identified in the Code-Projects Patient Record Management System version 1.0. The issue resides in the file 'xray_print.php', where the 'itr_no' parameter is manipulated, allowing for remote exploitation. This vulnerability enables attackers to execute arbitrary SQL commands, potentially leading to unauthorized access or modification of database information.

Impact

Exploitation of this vulnerability allows for arbitrary SQL command execution, which could be used to manipulate the database, extract sensitive information, or potentially escalate privileges within the application.

Reproduction

To reproduce this vulnerability, send a request to 'xray_print.php' with a crafted 'itr_no' parameter that includes SQL injection payloads. The lack of proper input sanitization will allow the injected SQL code to be executed by the database, demonstrating the vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
6.2
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.