CVE-2020-22170: SQL Injection
Published Jun 22, 2021
·Updated
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\getdoctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Affected Software
2 affected components
Phpgurukul Hospital Management System in PHP=4.0
Phpgurukul Hospital Management System=4.0
Event History
Jun 22, 2021
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-22170?
The severity of CVE-2020-22170 is high with a CVSS score of 7.5.
2
How can remote unauthenticated users exploit CVE-2020-22170?
Remote unauthenticated users can exploit CVE-2020-22170 by exploiting the SQL injection vulnerability in \hms\get_doctor.php to obtain database sensitive information.
3
What is the affected version of PHPGurukul Hospital Management System in PHP?
The affected version of PHPGurukul Hospital Management System in PHP is version 4.0.
4
Is there a fix available for CVE-2020-22170?
Yes, there is a fix available for CVE-2020-22170. Please refer to the provided reference link for more information on the fix.
5
What is the CWE ID of CVE-2020-22170?
The CWE ID of CVE-2020-22170 is 89.