CVE-2025-5298
HIGHCampcodes Online Hospital Management System 1.0 - SQL Injection via fromdate/todate Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-5298. PoCs published by Carine Constantino.
AI-analyzed exploit summary This is a detailed writeup describing SQL injection vulnerabilities in Campcodes Online Hospital Management System 1.0, specifically in the 'fromdate' and 'todate' fields of the betweendates-detailsreports.php endpoint. It includes SQLMap payloads for time-based blind, boolean-based blind, and UNION query techniques.
Description
A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/betweendates-detailsreports.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Exploits (1)
This is a detailed writeup describing SQL injection vulnerabilities in Campcodes Online Hospital Management System 1.0, specifically in the 'fromdate' and 'todate' fields of the betweendates-detailsreports.php endpoint. It includes SQLMap payloads for time-based blind, boolean-based blind, and UNION query techniques.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L