First published: Fri Jan 20 2023(Updated: )
SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on March 13, 2021), allows attackers to execute arbitrary commands via the contact and doctor parameters to /search.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hospital Management System Project Hospital Management System | <=2021-03-13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-48120 is critical.
CVE-2022-48120 allows attackers to execute arbitrary commands via the contact and doctor parameters to /search.php.
To fix CVE-2022-48120, update the kishan0725 Hospital Management System to a version released after March 13, 2021.
The Common Weakness Enumeration (CWE) ID associated with CVE-2022-48120 is CWE-89.
You can find more information about CVE-2022-48120 at the following link: https://github.com/kishan0725/Hospital-Management-System/issues/32