PHPGurukul Hospital Management System edit-doctor-specialization.php sql injection
CVE-2024-0360
Key Information:
- Vendor
- PHPGurukul
- Vendor
- CVE Published:
- 10 January 2024
Badges
Summary
A vulnerability exists within the PHPGurukul Hospital Management System 1.0, specifically in the processing of the file admin/edit-doctor-specialization.php. The issue arises from the improper handling of the argument 'doctorspecilization', which can lead to SQL injection attacks. Successful exploitation of this vulnerability may allow an attacker to manipulate the database, potentially leading to unauthorized data access or data corruption. Given that this vulnerability has already been disclosed publicly, users of the PHPGurukul Hospital Management System are urged to evaluate their systems for potential exposure and implement necessary countermeasures.
Affected Version(s)
Hospital Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved