SQL Injection Vulnerability in Hospital Management System by Truong Huuphuc
CVE-2022-24263

9.8CRITICAL

Key Information:

Vendor
PHPgurukul
Vendor
CVE Published:
31 January 2022

Summary

The Hospital Management System v4.0 has been identified to be vulnerable to an SQL injection flaw through the 'email' parameter in the func.php file. This vulnerability can potentially allow attackers to execute arbitrary SQL queries, leading to unauthorized access to sensitive database information or manipulation of the database itself. It is crucial for users of this system to implement appropriate security measures to safeguard against exploitation.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.