The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind SQL injection via the /medical/inventories.php path which allows attackers to retrieve all databases.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-06-02T16:50:08

Updated: 2024-08-04T15:19:09.332Z

Reserved: 2020-08-28T00:00:00

Link: CVE-2020-24862

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-06-02T17:15:08.547

Modified: 2021-06-09T17:01:30.937

Link: CVE-2020-24862

cve-icon Redhat

No data.