Record summary

CVE-2020-5192 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBHospital Management System 4.0 - 'searchdata' SQL InjectionExploitDB exploitby FULLSHADENot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHHospital Management System 4.0 - SQL InjectionCVSS 8.8

Hospital Management System 4.0 contains multiple SQL injection vulnerabilities because multiple pages and parameters do not validate user input. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Apply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in Hospital Management System 4.0.

WeaknessesCWE-89
AuthorsTenBird
Template tagscvecve2020hmscmssqliauthenticatededbphpgurukulvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:phpgurukul:hospital_management_system:4.0:*:*:*:*:*:*:*
Shodan: http.html:"hospital management system"
FOFA: body="hospital management system"

Source: ProjectDiscovery

References

3