


Perceptive Security
SOC/SIEM Consultancy

Clinic Pro contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the month par…
Published:
11 maart 2026 om 23:00:00
Alert date:
12 maart 2026 om 17:15:30
Source:
nvd.nist.gov
Web Technologies, Database & Storage
CVE-2019-25473 is a SQL injection vulnerability in Clinic Pro that affects the monthly_expense_overview endpoint. Authenticated attackers can manipulate database queries by injecting malicious SQL code through the month parameter. The vulnerability allows for multiple exploitation techniques including boolean-based blind, time-based blind, and error-based SQL injection. Successful exploitation can lead to extraction of sensitive database information. The vulnerability requires authentication but provides significant access to backend database contents once exploited.
Technical details
Mitigation steps:
Affected products:
Clinic Pro
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2019-25473
https://www.exploit-db.com/exploits/46642
https://www.vulncheck.com/advisories/clinic-pro-sql-injection-via-monthly-expense-overview-month-parameter
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
