PT-2024-38364 · Sourcecodester · Sourcecodester Clinics Patient Management System
Pengguogood
·
Published
2024-08-04
·
Updated
2024-09-07
·
CVE-2024-7454
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SourceCodester Clinics Patient Management System version 1.0
Description
A critical issue has been found in the function
patient name of the file patients.php, leading to sql injection. The attack may be launched remotely. This issue may result in potential sensitive data exposure.Recommendations
For SourceCodester Clinics Patient Management System version 1.0, patch immediately and validate inputs to resolve the issue. As a temporary workaround, consider restricting access to the
patient name function in the patients.php file until a patch is available.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Clinics Patient Management System