CVE-2025-3243Exploit(code-projects / patient_record_management_system)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for code-projects patient_record_management_system systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dental_form.php. The manipulation of the argument itr_no/dental_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • patient_record_management_system

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
patient_record_management_system

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-17: 2PoC Mentioned / Linked · 2026-08-17: 1Exploit Tool / Code · 2026-08-17: 108-17
Signal classification2 categories
Exploit
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-GH-EjpQM0Q [CRITICAL/PoC] Linked: CVE-2025-3243, CVE-2025-32433 CVE-2025-3243 🔗 https://exploitgrid.net/exploits/04f5ed1c-9f92-4e95-8e28-e010f831ef99

    Post summary

    The post provides a direct link to a functional exploit for CVE‑2025‑3243, confirming a PoC/exploit is available, but it offers no information on patches or real‑world usage.

    1000021
    33 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-GH-z2Wb7PG ( CVE-2026-72898 ) EGE-GH-UkSJfvx ( CVE-2026-73678 ) EGE-GH-MKUk78n ( CVE-2023-22621 ) EGE-GH-EjpQM0Q ( CVE-2025-3243, CVE-2025-32433 ) EGE-GH-seDm3r2 ( CVE-2025-55182 ) ..🧵👇

    Post summary

    The post merely enumerates several CVEs without further details, evidence of exploitation, or mitigation information.

    1000042
    33 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcode-projectspatient_record_management_system1.0--

Explore more