Kashipara Hospital Management System registration.php sql injection
CVE-2024-0268
Key Information:
- Vendor
Kashipara
- Vendor
- CVE Published:
- 7 January 2024
Badges
What is CVE-2024-0268?
A vulnerability has been identified in Kashipara Hospital Management System versions up to 1.0 that allows for SQL injection through the manipulation of input parameters such as name, email, pass, gender, age, and city within the registration.php file. This flaw permits an attacker to execute arbitrary SQL commands, which may compromise the integrity and confidentiality of sensitive data. The vulnerability can be exploited remotely, raising concerns for users relying on this system for patient management. Mitigation steps are crucial as the exploit details have been publicly disclosed.
Affected Version(s)
Hospital Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved