A vulnerability was found in kishan0725 Hospital Management System 4.0. It has been declared as critical. Affected is an unknown function of the file check_availability.php. The manipulation of the argument emailid/email results in sql injection.
This vulnerability is identified as CVE-2025-69949. The attack can be executed remotely. There is not any exploit available.