Featured image of post CVE-2025-53946

CVE-2025-53946

SQL Injection

CVE-2025-53946: SQL Injection Vulnerability in id_fichamedica Parameter on profile_paciente.php Endpoint

CVE Publication: https://www.cve.org/CVERecord?id=CVE-2025-53946

Summary

A SQL Injection vulnerability was discovered in the id_fichamedica parameter of the /html/saude/profile_paciente.php endpoint. This issue allows any unauthenticated attacker to inject arbitrary SQL queries, potentially leading to unauthorized data access or further exploitation depending on database configuration.

Details

The application fails to properly sanitize user-supplied input in the id_fichamedica parameter. As a result, specially crafted SQL payloads are interpreted directly by the backend database.

PoC

Vulnerable Endpoint: /html/saude/profile_paciente.php

Parameter: id_fichamedica

Payload:

1
  1+AND+SLEEP(10)

Manual Exploration:

Sqlmap:

Impact

  • Unauthorized access to sensitive data (e.g., users, passwords, logs).
  • Database enumeration (schemas, tables, users, versions).
  • Escalation to RCE depending on DB configuration (e.g., xp_cmdshell, UDFs).
  • Full compromise of the application if chained with other vulnerabilities.
  • This issue affects all users and environments, as it does not require authentication and is reachable via a public endpoint.

Reference

https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-532r-mgxv-g7jm

Finder

Marcelo Queiroz

Contributor

Natan Maia Morette

By: CVE-Hunters

Built with Hugo
Theme Stack designed by Jimmy