CVE-2024-12969: code-projects Hospital Management System Login index.php sql injection
A vulnerability, which was classified as critical, has been found in code-projects Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/index.php of the component Login. The manipulation of the argument username/password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12969?
CVE-2024-12969 is classified as a critical vulnerability.
What is affected by CVE-2024-12969?
CVE-2024-12969 affects the login functionality in the Hospital Management System 1.0.
How does CVE-2024-12969 work?
CVE-2024-12969 allows for SQL injection through the manipulation of the username and password arguments.
How can I fix CVE-2024-12969?
To fix CVE-2024-12969, ensure to implement parameterized queries and proper input validation for the login credentials.
Which version of Hospital Management System is impacted by CVE-2024-12969?
CVE-2024-12969 impacts Hospital Management System version 1.0.