CVE-2023-37069

CRITICAL

Online Hospital Management System V1.0 - SQL Injection via Login ID and Password Fields

Title source: llm
STIX 2.1

Description

Code-Projects Online Hospital Management System V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the login id and password fields during the login process, enabling an attacker to inject malicious SQL code.

Scores

CVSS v3 9.8
EPSS 0.0081
EPSS Percentile 52.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
online_hospital_management_system_project/online_hospital_management_system 1.0
Published Aug 10, 2023
Tracked Since Feb 18, 2026