First published: Thu Feb 10 2022(Updated: )
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hospital Management System Project Hospital Management System | =4.0 | |
PHPGURUKUL Hospital Management System | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-24646 is high with a CVSS score of 7.5.
CVE-2022-24646 affects Hospital Management System v4.0.
CVE-2022-24646 is a SQL injection vulnerability that can be exploited through the 'txtMsg' parameter of the contact.php file, allowing an attacker to execute malicious SQL queries and gain unauthorized access to the database.
At the moment, there is no official fix available for CVE-2022-24646. It is recommended to apply security patches or updates provided by the vendor once they become available.
You can find more information about CVE-2022-24646 on the following references: [link1], [link2], [link3].