CVE-2020-22172: SQL Injection
Published Jun 22, 2021
·Updated
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\getdoctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Affected Software
2 affected components
Phpgurukul Hospital Management System in PHP=4.0
Phpgurukul Hospital Management System=4.0
Event History
Jun 22, 2021
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
Description
Frequently Asked Questions
1
What is CVE-2020-22172?
CVE-2020-22172 is a SQL injection vulnerability in PHPGurukul Hospital Management System in PHP v4.0.
2
How can a remote unauthenticated user exploit CVE-2020-22172?
A remote unauthenticated user can exploit CVE-2020-22172 to obtain database sensitive information.
3
What is the severity of CVE-2020-22172?
CVE-2020-22172 has a severity value of 7.5, which is categorized as high severity.
4
What is the affected software of CVE-2020-22172?
CVE-2020-22172 affects PHPGurukul Hospital Management System in PHP v4.0.
5
Is there any fix available for CVE-2020-22172?
As of now, there is no known fix available for CVE-2020-22172. It is recommended to follow the vendor's advisory or security recommendations.