PHPGurukul Hospital Management System query-details.php sql injection
CVE-2024-0364
Key Information:
- Vendor
- PHPGurukul
- Vendor
- CVE Published:
- 10 January 2024
Badges
Summary
A vulnerability exists in the PHPGurukul Hospital Management System version 1.0, specifically within the file admin/query-details.php. An attacker can exploit the application by manipulating the adminremark argument, which leads to SQL injection. This flaw allows unauthorized users to execute arbitrary SQL commands against the database, potentially compromising sensitive information and the integrity of the system. The vulnerability has been publicly disclosed and poses a significant risk to organizations utilizing this hospital management software, necessitating immediate attention and mitigation to prevent exploitation.
Affected Version(s)
Hospital Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved