PT-2021-23896 · Projectworlds · Projectworlds Hospital Management System

Khanhchauminh

·

Published

2021-12-22

·

Updated

2021-12-28

·

CVE-2021-43631

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Projectworlds Hospital Management System version 1.0
Description: The issue allows for SQL injection via the appointment no parameter in the "payment.php" endpoint.
Recommendations: For Projectworlds Hospital Management System version 1.0, avoid using the appointment no parameter in the payment.php endpoint until the issue is resolved. Consider temporarily restricting access to the payment.php endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43631

Affected Products

Projectworlds Hospital Management System