SQL Injection Vulnerability in Hospital Management System by Truong Huuphuc
CVE-2022-24263
9.8CRITICAL
Summary
The Hospital Management System v4.0 has been identified to be vulnerable to an SQL injection flaw through the 'email' parameter in the func.php file. This vulnerability can potentially allow attackers to execute arbitrary SQL queries, leading to unauthorized access to sensitive database information or manipulation of the database itself. It is crucial for users of this system to implement appropriate security measures to safeguard against exploitation.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved