SQL Injection Vulnerability in Code-Projects E-Health Care System
CVE-2024-10809
Key Information:
- Vendor
- Code-projects
- Status
- Vendor
- CVE Published:
- 5 November 2024
Badges
Summary
A serious SQL Injection vulnerability exists in the Code-Projects E-Health Care System version 1.0, specifically in the /Doctor/chat.php file. This flaw permits attackers to manipulate input parameters, notably 'name' and 'message', to execute unauthorized SQL queries on the database. The vulnerability can be exploited remotely, allowing adversaries to gain unauthorized access to sensitive data. Given the potential impact of this exploit and its public disclosure, immediate action is recommended for users to secure their applications against possible attacks.
Affected Version(s)
E-Health Care System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved