SQL Injection Vulnerability in SourceCodester Clinics Patient Management System
CVE-2024-7930
8.8HIGH
What is CVE-2024-7930?
A serious vulnerability has been identified in the SourceCodester Clinics Patient Management System version 1.0, specifically in the /pms/ajax/get_packings.php file. The flaw arises from improper handling of the medicine_id parameter, which allows for SQL injection attacks. This remote exploitation can lead to unauthorized access to the database, resulting in potential data breaches, data manipulation, or denial of service. Given that this vulnerability has been publicly disclosed, it poses a significant risk to systems running the affected version. Immediate remediation is advised to safeguard sensitive patient information.