CVE-2022-2298: SourceCodester Clinics Patient Management System Login Page index.php sql injection
A vulnerability has been found in SourceCodester Clinics Patient Management System 2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pms/index.php of the component Login Page. The manipulation of the argument username with the input admin' or '1'='1 leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2298?
The severity of CVE-2022-2298 is classified as critical.
How do I fix CVE-2022-2298?
To fix CVE-2022-2298, you should update the Clinic's Patient Management System to the latest version that addresses this vulnerability.
What component is affected by CVE-2022-2298?
CVE-2022-2298 affects the login page functionality in the file /pms/index.php.
What type of vulnerability is CVE-2022-2298?
CVE-2022-2298 is an SQL Injection vulnerability.
Which versions of the software are vulnerable to CVE-2022-2298?
Versions of the Clinic's Patient Management System that are affected by CVE-2022-2298 are specifically 2.0.