SQL Injection Vulnerability in PHPGurukul Hospital Management System by PHPGurukul
CVE-2020-22164
7.5HIGH
Summary
The PHPGurukul Hospital Management System, specifically version 4.0, is susceptible to a SQL injection flaw located in the check_availability.php file. This vulnerability allows remote unauthenticated users to craft malicious queries that can manipulate the underlying SQL database. By exploiting this weakness, attackers can potentially gain access to sensitive information stored within the database, posing a significant risk to data integrity and privacy.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved