First published: Tue Mar 15 2022(Updated: )
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hospital Management System Project Hospital Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25490 is a SQL injection vulnerability found in HMS v1.0 via the editid parameter in department.php.
CVE-2022-25490 has a severity rating of 9.8 (Critical).
CVE-2022-25490 allows an attacker to perform SQL injection attacks in HMS v1.0 by exploiting the vulnerable editid parameter in department.php.
Yes, it is recommended to apply the latest security patch or update provided by the Hospital Management System Project for HMS v1.0 to mitigate the SQL injection vulnerability.
You can find more information about CVE-2022-25490 at the following link: [CVE-2022-25490](https://github.com/kabirkhyrul/HMS/discussions/8)