CVE-2020-26627: SQL Injection
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under the 'Contact Us Queries -> Unread Query' tab.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26627?
The CVE-2020-26627 vulnerability is considered to have a high severity due to its potential impact on database confidentiality.
How do I fix CVE-2020-26627?
To mitigate CVE-2020-26627, ensure that input validation and parameter binding are implemented properly to prevent SQL injection.
What systems are affected by CVE-2020-26627?
CVE-2020-26627 affects Hospital Management System version 4.0.
What type of attack does CVE-2020-26627 facilitate?
CVE-2020-26627 facilitates time-based SQL injection attacks allowing unauthorized access to database information.
Can CVE-2020-26627 allow data leakage?
Yes, CVE-2020-26627 can allow attackers to leak sensitive data from the database through crafted payloads.