CVE-2024-7930: SourceCodester Clinics Patient Management System get_packings.php sql injection
A vulnerability has been found in SourceCodester Clinics Patient Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pms/ajax/getpackings.php. The manipulation of the argument medicineid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7930?
CVE-2024-7930 is classified as a critical vulnerability.
How does CVE-2024-7930 affect the system?
CVE-2024-7930 allows for SQL injection through the manipulation of the medicine_id argument in /pms/ajax/get_packings.php.
Which version of the software is vulnerable to CVE-2024-7930?
The vulnerability CVE-2024-7930 affects version 1.0 of the Oretnom23 Clinic Patient Management System.
How can I mitigate CVE-2024-7930?
To mitigate CVE-2024-7930, validate and sanitize input parameters for the medicine_id in the affected file.
What should I do if I am affected by CVE-2024-7930?
If affected by CVE-2024-7930, it is advisable to apply the necessary patches or updates as soon as they are available.