First published: Fri Oct 28 2022(Updated: )
Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hospital Management System Project Hospital Management System | =4.0 | |
=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35387 is a vulnerability in Hospital Management System v 4.0 that allows for SQL Injection via the file hospital/hms/admin/view-patient.php.
CVE-2021-35387 has a severity keyword of high and a severity value of 8.8.
CVE-2021-35387 affects Hospital Management System v 4.0 by allowing an attacker to perform SQL Injection through the file hospital/hms/admin/view-patient.php.
To fix CVE-2021-35387, you should update Hospital Management System to a version that is not vulnerable or apply patches provided by the vendor.
CWE-89 is a category of vulnerability known as SQL Injection, which allows attackers to execute arbitrary SQL commands on a database.