First published: Wed Feb 23 2022(Updated: )
An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hospital Management System Project Hospital Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25402 has a severity rating of critical (9.1).
CVE-2022-25402 is an incorrect access control issue in HMS v1.0 that allows unauthenticated attackers to read and modify all PHP files.
CVE-2022-25402 affects Hospital Management System (HMS) v1.0 by allowing unauthenticated attackers to read and modify all PHP files.
No, authentication is not required to exploit CVE-2022-25402.
Yes, you can find more information about CVE-2022-25402 at the following reference: https://github.com/dota-st/Vulnerability/blob/master/HMS/HMS.md