CVE-2022-48120 — SQL Injection in Management System Project Hospital Management System

CWE-89 — SQL Injection3 documents3 sources
Severity
9.8CRITICALNVD
EPSS
0.3%
top 43.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 20

Description

SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on March 13, 2021), allows attackers to execute arbitrary commands via the contact and doctor parameters to /search.php.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
CVE-2022-48120: SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on March 13, 2021), allows↗2023-01-20
â–¶
GHSA
GHSA-jhx2-qrv5-m4q7: SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on March 13, 2021), allows↗2023-01-20
â–¶
CVE-2022-48120 — SQL Injection | cvebase