CVE-2022-48120
Last modified
CVE-2022-48120 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on March 13, 2021), allows attackers to execute arbitrary commands via the contact and doctor parameters to /search.php.. EPSS estimates a 0.87% chance of exploitation in the next 30 days.
Description
SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on March 13, 2021), allows attackers to execute arbitrary commands via the contact and doctor parameters to /search.php.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hospital Management System Project | Hospital Management System | <= 2021-03-13 |
References
- https://github.com/kishan0725/Hospital-Management-System/issues/32Exploit, Issue Tracking, Third Party Advisory
- https://github.com/kishan0725/Hospital-Management-System/issues/32Exploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-48120?
How severe is CVE-2022-48120?
How do I fix CVE-2022-48120?
Are you affected by CVE-2022-48120?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
