CVE-2023-37069

CRITICAL

Online Hospital Management System - SQL Injection

Title source: rule
STIX 2.1

Description

Code-Projects Online Hospital Management System V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the login id and password fields during the login process, enabling an attacker to inject malicious SQL code.

Scores

CVSS v3 9.8
EPSS 0.0009
EPSS Percentile 25.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
online_hospital_management_system_project/online_hospital_management_system 1.0
Published Aug 10, 2023
Tracked Since Feb 18, 2026