PT-2024-38562 · Sourcecodester · Sourcecodester Clinics Patient Management System

Wsstiger

+1

·

Published

2024-08-13

·

Updated

2024-08-19

·

CVE-2024-7754

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Clinics Patient Management System version 1.0
Description A critical issue affects the processing of the file /ajax/check medicine name.php, where the manipulation of the user name argument leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations For SourceCodester Clinics Patient Management System version 1.0, consider disabling the /ajax/check medicine name.php file or restricting access to it until a patch is available. Additionally, avoid using the user name argument in the affected API endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-7754

Affected Products

Sourcecodester Clinics Patient Management System