vendor:
Clinic Pro - Clinic Management Software
by:
Abdullah Çelebi
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Clinic Pro - Clinic Management Software
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WAMPP @Win
2019
Clinic Pro – Clinic Management Software
An attacker can access all data following an authorized user login using the parameter. The Proof of Concept (POC) includes three types of SQLi: boolean-based blind, time-based blind, and error-based.
Mitigation:
Input validation and sanitization should be used to prevent SQL injection attacks.