PT-2024-33159 · Unknown · Online Clinic Management System

Jacky.Liu

·

Published

2024-10-21

·

Updated

2025-07-07

·

CVE-2024-48597

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Online Clinic Management System version 1.0
Description The issue is related to a SQL injection vulnerability. This vulnerability can be exploited via the id parameter at the "/success/editp.php?action=edit" API endpoint.
Recommendations For Online Clinic Management System version 1.0, consider restricting access to the /success/editp.php?action=edit API endpoint to minimize the risk of exploitation. Avoid using the id parameter in this endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-48597

Affected Products

Online Clinic Management System