CVE-2022-25491: SQL Injection
Published Mar 15, 2022
·Updated
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php.
Affected Software
1 affected component
Hospital Management System Project Hospital Management System=1.0
Event History
Mar 15, 2022
CVE Published
via MITRE·05:38 PM
Data Sourced
via MITRE·05:38 PM
Description
Frequently Asked Questions
1
What is CVE-2022-25491?
CVE-2022-25491 is a SQL injection vulnerability in HMS v1.0.
2
How does the SQL injection vulnerability in HMS v1.0 work?
The vulnerability occurs via the editid parameter in appointment.php, allowing an attacker to execute arbitrary SQL queries.
3
What is the severity of CVE-2022-25491?
CVE-2022-25491 has a severity rating of 7.5 (High).
4
How can I fix the SQL injection vulnerability in HMS v1.0?
To fix the vulnerability, update HMS to a version that includes a patch for CVE-2022-25491.
5
Where can I find more information about CVE-2022-25491?
More information about CVE-2022-25491 can be found at the following link: [https://github.com/kabirkhyrul/HMS/discussions/8]