CVE-2024-10995: Codezips Hospital Appointment System removeDoctorResult.php sql injection
A vulnerability was found in Codezips Hospital Appointment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /removeDoctorResult.php. The manipulation of the argument Name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10995?
CVE-2024-10995 has been classified as a critical vulnerability.
How does CVE-2024-10995 affect the system?
CVE-2024-10995 allows for SQL injection through the manipulation of the argument Name in the file /removeDoctorResult.php.
What software versions are impacted by CVE-2024-10995?
CVE-2024-10995 affects Codezips Hospital Appointment System version 1.0.
How can I mitigate CVE-2024-10995?
To mitigate CVE-2024-10995, validate and sanitize all input parameters to prevent SQL injection.
Is it possible to exploit CVE-2024-10995 remotely?
Yes, CVE-2024-10995 can be exploited remotely by an attacker.