PT-2023-5592 · Unknown · Hospital Management System

CVE-2023-43909

·

Publicado

2023-02-11

·

Atualizado

2023-10-02

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Hospital Management System thru commit 4770d
Description The issue is related to a SQL injection vulnerability in the Hospital Management System. This vulnerability is exploited via the app contact parameter in the appsearch.php file. The vulnerability arises from the lack of protection against SQL query structure manipulation when processing the app contact parameter. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code.
Recommendations As a temporary workaround, consider restricting access to the appsearch.php file or disabling the app contact parameter until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06246
CVE-2023-43909

Produtos afetados

Hospital Management System