A vulnerability classified as critical has been found in Campcodes Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ of the component Admin Dashboard Login. This manipulation of the argument Password causes sql injection.

The identification of this vulnerability is CVE-2025-9770. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.