First published: Mon Nov 13 2023(Updated: )
SQL Injection vulnerability in hospitalLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'hemail' and 'hpassword' parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-46014 is medium with a CVSS score of 5.5.
An attacker can exploit CVE-2023-46014 by using SQL injection techniques to execute arbitrary SQL commands through the 'hemail' and 'hpassword' parameters in hospitalLogin.php.
The affected software of CVE-2023-46014 is Code-Projects Blood Bank 1.0.
To fix CVE-2023-46014, update the Code-Projects Blood Bank software to a version that has a fix for the SQL injection vulnerability.