vendor:
Hospital-Management
by:
Cakes
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Hospital-Management
Affected Version From: 1.26
Affected Version To: 1.26
Patch Exists: NO
Related CWE:
CPE: a:hospital-management_project:hospital-management:1.26
Platforms Tested: CentOS 7
2019
Hospital-Management 1.26 – ‘fname’ SQL Injection
Simple SQL injection after application authentication. The exploit includes boolean-based blind, error-based, and time-based blind techniques.
Mitigation:
The vendor should sanitize user input to prevent SQL injection attacks. Regular security audits should be performed.