First published: Mon Aug 21 2023(Updated: )
A vulnerability classified as critical has been found in SourceCodester Free Hospital Management System for Small Practices 1.0/5.0.12. Affected is an unknown function of the file vm\doctor\edit-doc.php. The manipulation of the argument id00/nic/oldemail/email/spec/Tele leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-237564.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mayurik Free Hospital Management System For Small Practices | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-4443 is critical with a score of 9.8.
CVE-2023-4443 affects SourceCodester Free Hospital Management System for Small Practices by allowing SQL injection through the manipulation of certain arguments.
The unknown function of the file vm\doctor\edit-doc.php is affected by CVE-2023-4443.
CVE-2023-4443 is associated with CWE ID 89.
To fix the SQL injection vulnerability in SourceCodester Free Hospital Management System for Small Practices, you should apply the latest security patches or updates provided by the vendor.