PT-2022-18130 · Sourcecodester · Sourcecodester Electronic Medical Records System

Hanfu

·

Published

2022-08-06

·

Updated

2022-08-11

·

CVE-2022-2693

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions SourceCodester Electronic Medical Records System (affected versions not specified)
Description A critical vulnerability has been found in the SourceCodester Electronic Medical Records System. This issue affects the file register.php of the component UPDATE Statement Handler. The manipulation of the pconsultation argument leads to SQL injection. The attack can be initiated remotely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-2693

Affected Products

Sourcecodester Electronic Medical Records System