Vulnerability Description
In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple parameters, and database information can be obtained through injection.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hospital Management System Project | Hospital Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/kabirkhyrul/HMS/discussions/15ExploitThird Party Advisory
- https://github.com/kabirkhyrul/HMS/tree/1.0Third Party Advisory
- https://github.com/kabirkhyrul/HMS/discussions/15ExploitThird Party Advisory
- https://github.com/kabirkhyrul/HMS/tree/1.0Third Party Advisory
FAQ
What is CVE-2022-30012?
CVE-2022-30012 is a vulnerability with a CVSS score of 7.5 (HIGH). In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple parameters, and database information can be obtained through injection.
How severe is CVE-2022-30012?
CVE-2022-30012 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-30012?
Check the references section above for vendor advisories and patch information. Affected products include: Hospital Management System Project Hospital Management System.