CVE-2022-38637
Hospital Management System 1.0 - SQL Injection
Record summary
CVE-2022-38637 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALHospital Management System 1.0 - SQL InjectionCVSS 9.8
Hospital Management System 1.0 contains a SQL injection vulnerability via the editid parameter in /HMS/user-login.php. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
Source: ProjectDiscovery