CVE-2020-22173: SQL Injection
Published Jun 22, 2021
·Updated
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Affected Software
2 affected components
Phpgurukul Hospital Management System in PHP=4.0
Phpgurukul Hospital Management System=4.0
Event History
Jun 22, 2021
CVE Published
via MITRE·02:07 PM
Data Sourced
via MITRE·02:07 PM
Description
Frequently Asked Questions
1
What is CVE-2020-22173?
CVE-2020-22173 is a SQL injection vulnerability in PHPGurukul Hospital Management System v4.0.
2
How severe is CVE-2020-22173?
CVE-2020-22173 has a severity rating of 7.5 (High).
3
How can the SQL injection vulnerability in PHPGurukul Hospital Management System v4.0 be exploited?
Remote unauthenticated users can exploit the vulnerability to obtain sensitive information from the database.
4
What is the affected software?
The affected software is PHPGurukul Hospital Management System in PHP v4.0.
5
Is there a fix available for CVE-2020-22173?
A fix for CVE-2020-22173 is not available at the moment, but implementing input validation and parameterized queries can help mitigate the vulnerability.