SQL Injection Vulnerability in Code-Projects E-Health Care System
CVE-2024-10740
Key Information:
- Vendor
Code-projects
- Status
- Vendor
- CVE Published:
- 3 November 2024
Badges
What is CVE-2024-10740?
A serious SQL injection vulnerability has been identified in the E-Health Care System by Code-Projects. The flaw lies within the /Admin/consulting_detail.php file and specifically involves the manipulation of the 'consulting_id' parameter. This vulnerability affects all versions of the product up to and including 1.0, permitting unauthorized users to execute arbitrary SQL queries. As a result, attackers can potentially gain access to sensitive information or compromise the integrity of the database. Exploitation can be conducted remotely, which heightens the urgency for affected users to apply any available patches or updates.
Affected Version(s)
E-Health Care System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved