First published: Sun May 26 2024(Updated: )
A vulnerability classified as critical has been found in SourceCodester Online Hospital Management System 1.0. Affected is an unknown function of the file departmentDoctor.php. The manipulation of the argument deptid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-266274 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
SourceCodester Online Hospital Management System | ||
Warrendaloyan Online Hospital Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5362 is classified as a critical severity vulnerability.
CVE-2024-5362 allows for SQL injection attacks via the deptid argument in the departmentDoctor.php file.
CVE-2024-5362 affects users of the SourceCodester Online Hospital Management System version 1.0.
To fix CVE-2024-5362, implement input validation and parameterized queries to prevent SQL injection.
Yes, CVE-2024-5362 can be exploited remotely if the system is accessible over the internet.