Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-78308
HistoryOct 17, 2023 - 12:00 a.m.

Free Hospital Management System SQL Injection Vulnerability

2023-10-1700:00:00
China National Vulnerability Database
www.cnvd.org.cn
3
hospital management system
sql injection
validation
search parameter
attack
database security

7.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

27.3%

The Free Hospital Management System is a computerized system that helps manage healthcare-related information and helps healthcare providers do their jobs efficiently. The Free Hospital Management System suffers from a SQL injection vulnerability that originates from a lack of validation of the search parameter in file /vm/admin/doctors.php against externally entered SQL statements, which can be exploited by an attacker to execute illegal SQL commands to steal sensitive database data.

7.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

27.3%

Related for CNVD-2023-78308