CVE-2024-10350: code-projects Hospital Management System add-doctor.php sql injection
A vulnerability was found in code-projects Hospital Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/add-doctor.php. The manipulation of the argument docname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10350?
CVE-2024-10350 has been declared as critical.
How do I fix CVE-2024-10350?
To fix CVE-2024-10350, you should sanitize user inputs in the /admin/add-doctor.php file to prevent SQL injection.
What vulnerabilities are associated with CVE-2024-10350?
CVE-2024-10350 is associated with an SQL injection vulnerability due to improper handling of the 'docname' argument.
Which software is affected by CVE-2024-10350?
CVE-2024-10350 affects version 1.0 of the Hospital Management System by Fabianros.
Can CVE-2024-10350 be exploited remotely?
Yes, CVE-2024-10350 can be exploited remotely through SQL injection.