First published: Fri Jul 21 2023(Updated: )
A vulnerability was found in Hospital Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file patientappointment.php. The manipulation of the argument loginid/password/mobileno/appointmentdate/appointmenttime/patiente/dob/doct/city leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235078 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hospital Management System Project Hospital Management System | =1.0 | |
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-3810 is critical.
The affected software version of CVE-2023-3810 is Hospital Management System 1.0.
The CWE ID of CVE-2023-3810 is CWE-89.
To fix the vulnerability in the Hospital Management System, apply the latest security patch or update provided by the vendor.
You can find more information about CVE-2023-3810 at the following references: [Reference 1](https://vuldb.com/?id.235078), [Reference 2](https://github.com/GZRsecurity/Cve-System/blob/main/Hospital%20Management%20System%20patientappointment.php%20has%20Sqlinjection.pdf), [Reference 3](https://vuldb.com/?ctiid.235078)