SQL Injection Vulnerability in Projectworlds Hospital Management System
CVE-2021-43628
9.8CRITICAL
What is CVE-2021-43628?
The Projectworlds Hospital Management System v1.0 is susceptible to a SQL injection attack through the email parameter in the hms-staff.php file. This vulnerability allows attackers to manipulate SQL queries, potentially leading to unauthorized access to sensitive information or administrative functionality. Proper input validation and sanitization measures should be implemented to safeguard against such threats.