Hospital Management System v4 was discovered to contain a SQL injection vulnerability in the doctorsearch.php file. The doctor_contact parameter is not properly sanitized before being used in SQL queries, allowing remote attackers to manipulate the database and potentially execute arbitrary code or disclose sensitive information.
SQL Injection
- Product Name: Hospital Management System
- Version: v4
- Component:
doctorsearch.php - Vendor: GitHub
- Repository: https://github.com/kishan0725/Hospital-Management-System
- Attack Type: Remote
- Attack Vector:
doctor_contactparameter - Impact:
- Code Execution
- Information Disclosure
Chaima EL BAHRAOUI