CVE-2022-27420: SQL Injection
Published May 4, 2022
·Updated
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the patientcontact parameter in patientsearch.php.
Affected Software
1 affected component
Hospital Management System Project Hospital Management System=1.0
Event History
May 4, 2022
CVE Published
via MITRE·02:23 AM
Data Sourced
via MITRE·02:23 AM
Description
Frequently Asked Questions
1
What is CVE-2022-27420?
CVE-2022-27420 is a SQL injection vulnerability in Hospital Management System v1.0.
2
How does the SQL injection vulnerability occur in Hospital Management System v1.0?
The vulnerability occurs via the patient_contact parameter in the patientsearch.php file in Hospital Management System v1.0.
3
What is the severity of CVE-2022-27420?
CVE-2022-27420 has a severity rating of 9.8, which is considered critical.
4
What is the Common Weakness Enumeration (CWE) number for CVE-2022-27420?
The Common Weakness Enumeration (CWE) number for CVE-2022-27420 is CWE-89.
5
Is there any reference or fix available for CVE-2022-27420?
Yes, you can find more information and a fix for CVE-2022-27420 at: https://github.com/kishan0725/Hospital-Management-System/issues/19