PT-2024-11735 · Unknown · Hospital Management System

Aaditya Singh Rajawat

·

Published

2024-03-07

·

Updated

2024-08-01

·

CVE-2022-46498

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hospital Management System version 1.0
Description A SQL injection issue was found in the Hospital Management System, specifically via the doc number parameter at the "his admin view single employee.php" endpoint.
Recommendations For Hospital Management System version 1.0, consider restricting access to the his admin view single employee.php endpoint until a patch is available, and avoid using the doc number parameter to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-46498

Affected Products

Hospital Management System