PT-2024-16290 · Unknown · Codezips Hospital Appointment System

Xu Rongda

·

Published

2024-10-28

·

Updated

2024-10-31

·

CVE-2024-10449

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Codezips Hospital Appointment System version 1.0
Description A critical issue was found in the system, affecting the /loginAction.php file. The manipulation of the Username argument leads to sql injection. This issue can be exploited remotely. The exploit has been publicly disclosed.
Recommendations For Codezips Hospital Appointment System version 1.0, consider restricting access to the /loginAction.php file until a patch is available. As a temporary workaround, avoid using the Username argument in the login action to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10449

Affected Products

Codezips Hospital Appointment System