CVE-2019-25473
HIGHClinic Pro - Authenticated SQL Injection via Monthly Expense Overview Month Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25473. PoCs published by Abdullah Çelebi.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Clinic Pro's monthly_expense_overview endpoint via the 'month' POST parameter. It includes boolean-based blind, time-based blind, and error-based SQLi payloads.
Description
Clinic Pro contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the month parameter. Attackers can send POST requests to the monthly_expense_overview endpoint with crafted month values using boolean-based blind, time-based blind, or error-based SQL injection techniques to extract sensitive database information.
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in Clinic Pro's monthly_expense_overview endpoint via the 'month' POST parameter. It includes boolean-based blind, time-based blind, and error-based SQLi payloads.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N