NA

CVE-2020-26630

Published: 10/01/2024 Updated: 16/01/2024
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

A Time-Based SQL Injection vulnerability exists in Hospital Management System V4.0 which can allow an malicious user to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an admin.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgurukul hospital management system 4.0

Exploits

Hospital Management System versions 40 and below suffer from cross site scripting, remote shell upload, and remote SQL injection vulnerabilities ...