CVE-2025-10618HIGH 8.8EPSS p34.8%
CVE-2025-10618CVE-2025-10618
Description
A security vulnerability has been detected in itsourcecode Online Clinic Management System 1.0. Affected by this issue is some unknown functionality of the file transact.php. Such manipulation of the argument firstname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. Other parameters might be affected as well.
Scoring
| CVSS 3.1 | 8.8 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.44% probability of exploitation · percentile 34.8% · 2026-06-18T12:00:27Z |
| Published | 2025-09-17 |
| Last modified | 2026-04-29 |
Underlying weaknesses· 2
References
- https://github.com/drew-byte/Online-Clinic-Management-System_TimeBasedSQLi_PoC/blob/main/README.md
- https://itsourcecode.com/
- https://vuldb.com/?ctiid.324645
- https://vuldb.com/?id.324645
- https://vuldb.com/?submit.650177
- https://github.com/drew-byte/Online-Clinic-Management-System_TimeBasedSQLi_PoC/blob/main/README.md
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 0% | live |
| Weakness | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')cwe-89 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.