A vulnerability, which was classified as critical, has been found in CodeZips Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /staff.php. The manipulation of the argument tel leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Dec 2024 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability, which was classified as critical, has been found in CodeZips Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /staff.php. The manipulation of the argument tel leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. | |
Title | CodeZips Hospital Management System staff.php sql injection | |
Weaknesses | CWE-74 CWE-89 |
|
References |
| |
Metrics |
cvssV2_0
|
MITRE
Status: PUBLISHED
Assigner: VulDB
Published: 2024-12-27T01:00:12.468Z
Updated: 2024-12-27T18:39:59.668Z
Reserved: 2024-12-26T17:11:27.505Z
Link: CVE-2024-12976
Vulnrichment
No data.
NVD
Status : Received
Published: 2024-12-27T02:15:06.063
Modified: 2024-12-27T02:15:06.063
Link: CVE-2024-12976
Redhat
No data.