CVE-2020-22165: SQL Injection
Published Jun 22, 2021
·Updated
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Affected Software
2 affected components
Phpgurukul Hospital Management System in PHP=4.0
Phpgurukul Hospital Management System=4.0
Event History
Jun 22, 2021
CVE Published
via MITRE·02:14 PM
Data Sourced
via MITRE·02:14 PM
Description
Frequently Asked Questions
1
What is CVE-2020-22165?
CVE-2020-22165 is a SQL injection vulnerability in PHPGurukul Hospital Management System in PHP v4.0.
2
How can remote unauthenticated users exploit CVE-2020-22165?
Remote unauthenticated users can exploit CVE-2020-22165 to obtain database sensitive information.
3
What is the severity of CVE-2020-22165?
The severity of CVE-2020-22165 is high with a CVSS score of 7.5.
4
How do I fix CVE-2020-22165?
To fix CVE-2020-22165, apply the latest security patches provided by PHPGurukul or upgrade to a secure version of the Hospital Management System.
5
What is CWE-89?
CWE-89 is a vulnerability in SQL injection, where an attacker can manipulate SQL queries through input data.