SQL Injection Vulnerabilities in Hospital Management System by Kishan0725
CVE-2023-41528
9.8CRITICAL
What is CVE-2023-41528?
The Hospital Management System v4, developed by Kishan0725, has been found to expose multiple SQL injection vulnerabilities through the contact.php interface. Specifically, the parameters txtname, txtphone, and txtmail are susceptible to malicious inputs, allowing attackers to manipulate database queries. This vulnerability can lead to unauthorized access to sensitive data, which could severely compromise the integrity and confidentiality of the information within the system.
