PoC Index

CVE-2025-9753

MEDIUM 4.8EPSS 0.3%

A vulnerability was detected in Campcodes Online Hospital Management System 1.0. The affected element is an unknown function of the file /admin/patient-search.php of the component Patient Search Module. Performing manipulation of the argument Search by Name Mobile No results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used. In Campcodes Online Hospital Management System 1.0 wurde eine Schwachstelle gefunden. Es ist betroffen eine unbekannte Funktion der Datei /admin/patient-search.php der Komponente Patient Search Module. Die Veränderung des Parameters Search by Name Mobile No resultiert in cross site scripting. Es ist möglich, den Angriff aus der Ferne durchzuführen. Die Ausnutzung wurde veröffentlicht und kann verwendet werden.

CVSS v4.0
1.9 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS v3.1
2.4 LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
CVSS v2.0
3.3 LOWAV:N/AC:L/Au:M/C:N/I:P/A:N
EPSS
0.29% chance of exploitation in the next 30 days, 22th percentile
Published
2025-09-01
Updated
2025-09-02

Proof-of-concept exploits (1)

References

Related