Vulnerability Description
SQL Injection Vulnerability in Care2x Open Source Hospital Information Management 2.7 Alpha via the (1) pday, (2) pmonth, and (3) pyear parameters in GET requests sent to /modules/nursing/nursing-station.php.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Care2X | Hospital Information Management System | <= 2.7 |
Related Weaknesses (CWE)
References
- https://securityforeveryone.com/blog/care2x-hospital-information-management-systThird Party Advisory
- https://www.exploit-db.com/exploits/50165ExploitThird Party AdvisoryVDB Entry
- https://securityforeveryone.com/blog/care2x-hospital-information-management-systThird Party Advisory
- https://www.exploit-db.com/exploits/50165ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2021-36351?
CVE-2021-36351 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SQL Injection Vulnerability in Care2x Open Source Hospital Information Management 2.7 Alpha via the (1) pday, (2) pmonth, and (3) pyear parameters in GET requests sent to /modules/nursing/nursing-stat...
How severe is CVE-2021-36351?
CVE-2021-36351 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-36351?
Check the references section above for vendor advisories and patch information. Affected products include: Care2X Hospital Information Management System.