CVE-2024-10987: code-projects E-Health Care System user_appointment.php sql injection
A vulnerability was found in code-projects E-Health Care System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Doctor/userappointment.php. The manipulation of the argument scheduleid/scheduledate/scheduleday/starttime/endtime/booking leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10987?
CVE-2024-10987 has been declared as critical due to its potential impact on the E-Health Care System.
What is affected by CVE-2024-10987?
CVE-2024-10987 affects the file /Doctor/user_appointment.php within version 1.0 of the Anisha E-Health Care System.
How do I fix CVE-2024-10987?
To fix CVE-2024-10987, it is recommended to upgrade the E-Health Care System to a patched version provided by the vendor.
What could be the implications of CVE-2024-10987?
The implications of CVE-2024-10987 could involve unauthorized access or manipulation of user appointment data.
Is CVE-2024-10987 actively being exploited?
As of now, there are no confirmed reports indicating active exploitation of CVE-2024-10987.