CVE-2022-48120: SQL Injection
Published Jan 20, 2023
·Updated
SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on March 13, 2021), allows attackers to execute arbitrary commands via the contact and doctor parameters to /search.php.
Affected Software
1 affected component
Hospital Management System Project Hospital Management System<=2021-03-13
Event History
Jan 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-48120?
The severity of CVE-2022-48120 is critical.
2
How does CVE-2022-48120 impact the kishan0725 Hospital Management System?
CVE-2022-48120 allows attackers to execute arbitrary commands via the contact and doctor parameters to /search.php.
3
How can I fix CVE-2022-48120?
To fix CVE-2022-48120, update the kishan0725 Hospital Management System to a version released after March 13, 2021.
4
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2022-48120?
The Common Weakness Enumeration (CWE) ID associated with CVE-2022-48120 is CWE-89.
5
Where can I find more information about CVE-2022-48120?
You can find more information about CVE-2022-48120 at the following link: https://github.com/kishan0725/Hospital-Management-System/issues/32