top of page
perceptive_background_267k.jpg

Clinic Pro contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the month par…

Published:

11 maart 2026 om 23:00:00

Alert date:

12 maart 2026 om 17:15:30

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage

CVE-2019-25473 is a SQL injection vulnerability in Clinic Pro that affects the monthly_expense_overview endpoint. Authenticated attackers can manipulate database queries by injecting malicious SQL code through the month parameter. The vulnerability allows for multiple exploitation techniques including boolean-based blind, time-based blind, and error-based SQL injection. Successful exploitation can lead to extraction of sensitive database information. The vulnerability requires authentication but provides significant access to backend database contents once exploited.

Technical details

Mitigation steps:

Affected products:

Clinic Pro

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page