← Zuruck zu CVEs
CVE-2022-48120
CRITICAL9.8
Beschreibung
SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on March 13, 2021), allows attackers to execute arbitrary commands via the contact and doctor parameters to /search.php.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht1/20/2023
Zuletzt geandert4/3/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
hospital_management_system_project:hospital_management_system
Schwachen (CWE)
CWE-89CWE-89
Referenzen
https://github.com/kishan0725/Hospital-Management-System/issues/32(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.