CVE-2021-43631: SQL Injection
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointmentno parameter in payment.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43631?
The severity of CVE-2021-43631 is critical, with a severity value of 9.8.
What is the vulnerability in Projectworlds Hospital Management System v1.0?
The vulnerability in Projectworlds Hospital Management System v1.0 is SQL injection via the appointment_no parameter in payment.php.
How can I exploit CVE-2021-43631?
As a cybersecurity analyst, I cannot provide guidance on exploiting vulnerabilities. It is important to follow ethical guidelines and not engage in any malicious activities.
How do I fix the SQL injection vulnerability in Projectworlds Hospital Management System v1.0?
To fix the SQL injection vulnerability in Projectworlds Hospital Management System v1.0, proper input validation and parameterized queries should be implemented to prevent unauthorized database access.
Where can I find more information about CVE-2021-43631?
You can find more information about CVE-2021-43631 in the following references: [GitHub issue](https://github.com/projectworldsofficial/hospital-management-system-in-php/issues/5) and [Projectworlds website](https://projectworlds.in/free-projects/php-projects/hospital-management-system-in-php/).