Record summary

CVE-2022-38637 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICALHospital Management System 1.0 - SQL InjectionCVSS 9.8

Hospital Management System 1.0 contains a SQL injection vulnerability via the editid parameter in /HMS/user-login.php. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-89
Authorsarafatansari
Template tagscvecve2022hmscmssqliauth-bypasshospital_management_system_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:hospital_management_system_project:hospital_management_system:1.0:*:*:*:*:*:*:*
Shodan: http.html:"Hospital Management System"
Shodan: http.html:"hospital management system"
FOFA: body="hospital management system"

Source: ProjectDiscovery

References

3