CVE-2024-48597: SQL Injection
Published Oct 21, 2024
·Updated
Online Clinic Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /success/editp.php?action=edit.
Affected Software
2 affected components
Unknown Online Clinic Management System
Angeljudesuarez Online Clinic Management System=1.0
Event History
Oct 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-48597?
CVE-2024-48597 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2024-48597?
To fix CVE-2024-48597, you should implement prepared statements or parameterized queries to sanitize user inputs.
3
What type of vulnerability is CVE-2024-48597?
CVE-2024-48597 is a SQL injection vulnerability that allows attackers to manipulate database queries.
4
Where is CVE-2024-48597 found in the software?
CVE-2024-48597 is found in the Online Clinic Management System at the id parameter in /success/editp.php when action is set to edit.
5
What is affected by CVE-2024-48597?
CVE-2024-48597 affects the Online Clinic Management System version 1.0.