SQL Injection Vulnerability in Code-Projects E-Health Care System
CVE-2024-10988
Key Information:
- Vendor
- Code-projects
- Status
- Vendor
- CVE Published:
- 8 November 2024
Badges
Summary
A critical security flaw has been identified in the Code-Projects E-Health Care System version 1.0, which is vulnerable to SQL injection via the /Doctor/doctor_login.php endpoint. Attackers can exploit this vulnerability by manipulating the 'email' parameter, potentially allowing unauthorized access to the underlying database. This security issue could enable remote attackers to execute arbitrary SQL commands, leading to data breaches or compromised data integrity. It's crucial for users and organizations employing this system to apply appropriate security measures and stay updated on available patches.
Affected Version(s)
E-Health Care System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved