CVE-2022-30012SQL Injection in Management System Project Hospital Management System

CWE-89SQL Injection3 documents3 sources
Severity
7.5HIGHNVD
EPSS
0.3%
top 47.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 16
Latest updateMay 17

Description

In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple parameters, and database information can be obtained through injection.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

🔴Vulnerability Details

2
GHSA
GHSA-h8p9-8p5m-2m7h: In the POST request of the appointment2022-05-17
CVEList
CVE-2022-30012: In the POST request of the appointment2022-05-16
CVE-2022-30012 — SQL Injection | cvebase