First published: Wed Jan 10 2024(Updated: )
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an admin.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHPGURUKUL Hospital Management System | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26630 is considered a high severity vulnerability due to its potential to expose sensitive database information.
To fix CVE-2020-26630, ensure that Hospital Management System V4.0 is updated to the latest patch that addresses SQL Injection vulnerabilities.
CVE-2020-26630 specifically affects PHPGURUKUL Hospital Management System version 4.0.
CVE-2020-26630 facilitates time-based SQL Injection attacks that can lead to unauthorized database access.
Yes, CVE-2020-26630 can be exploited remotely by authenticated users with access to the 'Doctor Specialization' field.