CVE-2025-57254 | Karthikg1908 Hospital Management System 1.0 POST Parameter user-login.php username/password sql injection
A vulnerability marked as critical has been reported in Karthikg1908 Hospital Management System 1.0. Affected is an unknown function of the file user-login.php of the component POST Parameter Handler. The manipulation of the argument username/password leads to sql injection.
This vulnerability is referenced as CVE-2025-57254. Remote exploitation of the attack is possible. No exploit is available.