CVE-2022-3956

MEDIUM

HHIMS 2.1 - SQL Injection via Patient Portrait Handler PID Argument

Title source: llm
STIX 2.1

Description

A vulnerability classified as critical has been found in tsruban HHIMS 2.1. Affected is an unknown function of the component Patient Portrait Handler. The manipulation of the argument PID leads to sql injection. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. VDB-213462 is the identifier assigned to this vulnerability.

References (2)

Core 2
Core References
Exploit, Issue Tracking, Third Party Advisory
https://github.com/tsruban/HHIMS/issues/1
Permissions Required, Third Party Advisory, VDB Entry
https://vuldb.com/?id.213462

Scores

CVSS v3 6.3
EPSS 0.0066
EPSS Percentile 46.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-89 CWE-707
Status published
Products (1)
hhims_project/hhims 2.1
Published Nov 11, 2022
Tracked Since Feb 18, 2026