SQL Injection Vulnerability in SourceCodester Online Hospital Management System
CVE-2024-5362
Key Information:
- Vendor
- Sourcecodester
- Vendor
- CVE Published:
- 26 May 2024
Badges
Summary
A critical vulnerability has been identified in the SourceCodester Online Hospital Management System 1.0, specifically in the file departmentDoctor.php. This vulnerability arises from improper handling of the 'deptid' argument, enabling attackers to exploit SQL injection techniques. With this flaw, attackers can execute arbitrary SQL queries on the database, potentially compromising sensitive information and system integrity. This vulnerability is accessible for exploitation remotely and has been publicly disclosed, raising immediate concerns for organizations using this outdated software version.
Affected Version(s)
Online Hospital Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved