Vulnerability Description
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpgurukul | Hospital Management System | 4.0 |
Related Weaknesses (CWE)
References
- https://github.com/kishan0725/Hospital-Management-System/issues/18ExploitIssue TrackingThird Party Advisory
- https://github.com/nu11secur1ty/CVE-mitre/tree/main/2022/CVE-2022-24263ExploitThird Party Advisory
- https://www.nu11secur1ty.com/2022/02/cve-2022-24263.htmlExploitThird Party Advisory
- https://github.com/kishan0725/Hospital-Management-System/issues/18ExploitIssue TrackingThird Party Advisory
- https://github.com/nu11secur1ty/CVE-mitre/tree/main/2022/CVE-2022-24263ExploitThird Party Advisory
- https://www.nu11secur1ty.com/2022/02/cve-2022-24263.htmlExploitThird Party Advisory
FAQ
What is CVE-2022-24646?
CVE-2022-24646 is a vulnerability with a CVSS score of 7.5 (HIGH). Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.
How severe is CVE-2022-24646?
CVE-2022-24646 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-24646?
Check the references section above for vendor advisories and patch information. Affected products include: Phpgurukul Hospital Management System.