First published: Thu Mar 07 2024(Updated: )
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHPGurukul Hospital Management System | =1.0 | |
Unknown Hospital Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46498 is considered a high severity vulnerability due to its potential to enable SQL injection attacks.
To fix CVE-2022-46498, validate and sanitize user inputs for the doc_number parameter to prevent SQL injection.
CVE-2022-46498 can be exploited to execute unauthorized SQL commands, potentially leading to data leakage or manipulation.
CVE-2022-46498 affects version 1.0 of the Hospital Management System.
As of now, no official patch has been released specifically for CVE-2022-46498, so manual mitigation is recommended.