github.comexploit
https://github.com/Xu-Mingming/cve/blob/main/sql4.md CVE-2024-6969
MEDIUM
SourceCodester Clinics Patient Management System get_patient_history.php sql injection
Record summary
CVE-2024-6969 has a selected CVSS score of 5.3 (medium).
Description
A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /ajax/get_patient_history.php. The manipulation of the argument patient_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272123.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 22, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Clinics Patient Management SystemBrowse SourceCodester / Clinics Patient Management SystemDefault status: unknown | CVE List | 1.0 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-6969 VDB-272123 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.272123 VDB-272123 | SourceCodester Clinics Patient Management System get_patient_history.php sql injectionvdb entryTechnical description
https://vuldb.com/?id.272123 Submit #378108 | SourceCodester Clinic's Patient Management System 1.0 SQL injection vulnerabilityThird-party advisory
https://vuldb.com/?submit.378108