First published: Sun Aug 06 2023(Updated: )
A vulnerability classified as critical has been found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected is an unknown function of the file /vm/doctor/doctors.php?action=view. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-236214 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mayurik Free Hospital Management System For Small Practices | =1.0 | |
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4179 is a critical vulnerability found in SourceCodester Free Hospital Management System for Small Practices 1.0.
CVE-2023-4179 is classified as critical with a severity score of 9.8 out of 10.
CVE-2023-4179 affects an unknown function in the file /vm/doctor/doctors.php?action=view, allowing for SQL injection via the manipulated argument id.
The SQL injection vulnerability in the SourceCodester Free Hospital Management System can be exploited by manipulating the argument id in the /vm/doctor/doctors.php?action=view URL.
At the moment, there is no known fix or patch available for CVE-2023-4179. It is recommended to follow any updates from the software vendor for future patches or mitigation steps.