CVE-2020-5192
Hospital Management System 4.0 - 'searchdata' SQL Injection
Record summary
CVE-2020-5192 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBHospital Management System 4.0 - 'searchdata' SQL InjectionExploitDB exploitby FULLSHADENot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHHospital Management System 4.0 - SQL InjectionCVSS 8.8
Hospital Management System 4.0 contains multiple SQL injection vulnerabilities because multiple pages and parameters do not validate user input. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Apply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in Hospital Management System 4.0.
Source: ProjectDiscovery