CVE-2020-22175: SQL Injection
Published Jun 22, 2021
·Updated
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Affected Software
2 affected components
Phpgurukul Hospital Management System in PHP=4.0
Phpgurukul Hospital Management System=4.0
Event History
Jun 22, 2021
CVE Published
via MITRE·02:04 PM
Data Sourced
via MITRE·02:04 PM
Description
Frequently Asked Questions
1
What is CVE-2020-22175?
CVE-2020-22175 is a SQL injection vulnerability in PHPGurukul Hospital Management System in PHP v4.0.
2
How severe is CVE-2020-22175?
CVE-2020-22175 has a severity rating of 7.5, which is considered high.
3
How can remote unauthenticated users exploit CVE-2020-22175?
Remote unauthenticated users can exploit CVE-2020-22175 to obtain sensitive information from the database.
4
What is the affected software?
The affected software is PHPGurukul Hospital Management System in PHP v4.0.
5
How can I fix CVE-2020-22175?
To fix CVE-2020-22175, update PHPGurukul Hospital Management System to a version that has patched the SQL injection vulnerability.