vendor:
Online Nurse Hiring System
by:
Alperen Yozgat
6.1
CVSS
HIGH
Time-Based SQL Injection
89
CWE
Product Name: Online Nurse Hiring System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: CVE-2023-XXXX
CPE: a:phpgurukul:online_nurse_hiring_system:1.0
Platforms Tested: Kali Linux 6.1.27-1kali1 (2023-05-12) x86_64 + XAMPP 7.4.30
2023
Online Nurse Hiring System 1.0 – ‘bookid’ Time-Based SQL Injection
The 'bookid' parameter in Online Nurse Hiring System 1.0 is susceptible to Time-Based SQL Injection, allowing attackers to manipulate the SQL query execution time.
Mitigation:
To mitigate this vulnerability, input validation and parameterized queries should be implemented to prevent SQL Injection attacks.