PT-2020-18293 · Phpgurukul · Phpgurukul Hospital Management System
Fullshade
·
Published
2020-01-06
·
Updated
2023-11-14
·
CVE-2020-5192
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PHPGurukul Hospital Management System version 4.0
Description
The issue concerns multiple SQL injection vulnerabilities. These vulnerabilities arise because multiple pages and parameters within the application do not properly validate user input. As a result, the application's database and information can be fully compromised.
Recommendations
For PHPGurukul Hospital Management System version 4.0, consider implementing proper input validation and sanitization for all user-input parameters to prevent SQL injection attacks. Additionally, restrict access to sensitive database information and ensure that all database interactions are securely handled. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpgurukul Hospital Management System