First published: Mon Jan 31 2022(Updated: )
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hospital Management System Project Hospital Management System | =4.0 | |
PHPGURUKUL Hospital Management System | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24263 is a SQL injection vulnerability in Hospital Management System v4.0.
CVE-2022-24263 allows attackers to execute arbitrary SQL commands via the email parameter in the func.php file.
CVE-2022-24263 has a severity rating of 9.8 (critical).
To fix CVE-2022-24263, it is recommended to apply the necessary security patches or updates provided by the Hospital Management System project.
You can find more information about CVE-2022-24263 at the following references: [http://packetstormsecurity.com/files/165882/Hospital-Management-System-4.0-SQL-Injection.html](http://packetstormsecurity.com/files/165882/Hospital-Management-System-4.0-SQL-Injection.html), [https://github.com/kishan0725/Hospital-Management-System/issues/17](https://github.com/kishan0725/Hospital-Management-System/issues/17), [https://github.com/nu11secur1ty/CVE-mitre/tree/main/2022/CVE-2022-24263](https://github.com/nu11secur1ty/CVE-mitre/tree/main/2022/CVE-2022-24263).