CVE-2022-25490: SQL Injection
Published Mar 15, 2022
·Updated
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.
Affected Software
1 affected component
Hospital Management System Project Hospital Management System=1.0
Event History
Mar 15, 2022
CVE Published
via MITRE·05:40 PM
Data Sourced
via MITRE·05:40 PM
Description
Frequently Asked Questions
1
What is CVE-2022-25490?
CVE-2022-25490 is a SQL injection vulnerability found in HMS v1.0 via the editid parameter in department.php.
2
How severe is CVE-2022-25490?
CVE-2022-25490 has a severity rating of 9.8 (Critical).
3
How does CVE-2022-25490 affect the Hospital Management System (HMS) v1.0?
CVE-2022-25490 allows an attacker to perform SQL injection attacks in HMS v1.0 by exploiting the vulnerable editid parameter in department.php.
4
Is there a fix for CVE-2022-25490?
Yes, it is recommended to apply the latest security patch or update provided by the Hospital Management System Project for HMS v1.0 to mitigate the SQL injection vulnerability.
5
Where can I find more information about CVE-2022-25490?
You can find more information about CVE-2022-25490 at the following link: [CVE-2022-25490](https://github.com/kabirkhyrul/HMS/discussions/8)