PT-2022-24494 · Unknown · Hospital Management System

Tutuba

·

Published

2022-09-13

·

Updated

2022-09-16

·

CVE-2022-38637

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hospital Management System version 1.0
Description The issue is related to multiple SQL injection vulnerabilities. These vulnerabilities can be exploited via the Username and Password parameters on the Login page, specifically the '/login' API endpoint.
Recommendations For Hospital Management System version 1.0, consider temporarily disabling the login functionality until a patch is available. Restrict access to the login page to minimize the risk of exploitation. Avoid using the Username and Password parameters in the affected login endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-38637

Affected Products

Hospital Management System