go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Le-show Medical Practice Management System - SQL Injection

TVN ID TVN-202504008
CVE ID CVE-2025-3708
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products Le-show version V3.0.25 and earlier
Description Le-show medical practice management system from Le-yan has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Solution Update to version V3.0.30 or later
Credit Lucas Yang (SIHAN YANG), Yuru Sung
Public Date 2025-04-30
Top