CVE-2022-3956

MEDIUM

Hhims - SQL Injection

Title source: rule
STIX 2.1

Description

A vulnerability classified as critical has been found in tsruban HHIMS 2.1. Affected is an unknown function of the component Patient Portrait Handler. The manipulation of the argument PID leads to sql injection. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. VDB-213462 is the identifier assigned to this vulnerability.

Scores

CVSS v3 6.3
EPSS 0.0036
EPSS Percentile 57.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-89 CWE-707
Status published
Products (1)
hhims_project/hhims 2.1
Published Nov 11, 2022
Tracked Since Feb 18, 2026