Hospital Management System Project ≫ Hospital Management System
45 Schwachstellen gefunden.
CVE-2021-44095
- EPSS 0.6%
- Veröffentlicht 02.06.2022 14:15:31
- Zuletzt bearbeitet 21.11.2024 06:30:21
A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote attacker to compromise Application SQL database.
CVE-2022-30516
- EPSS 0.22%
- Veröffentlicht 26.05.2022 17:15:09
- Zuletzt bearbeitet 21.11.2024 07:02:51
In Hospital-Management-System v1.0, the editid parameter in the doctor.php page is vulnerable to SQL injection attacks.
CVE-2022-30012
- EPSS 0.29%
- Veröffentlicht 16.05.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 07:02:04
In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple parameters, and database information can be obtained through injection.
CVE-2022-30011
- EPSS 1.26%
- Veröffentlicht 16.05.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 07:02:04
In HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability.
CVE-2022-28929
- EPSS 0.22%
- Veröffentlicht 15.05.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:58:12
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the delid parameter at viewtreatmentrecord.php.
CVE-2022-30449
- EPSS 0.21%
- Veröffentlicht 11.05.2022 19:15:07
- Zuletzt bearbeitet 21.11.2024 07:02:45
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php.
CVE-2022-30448
- EPSS 0.34%
- Veröffentlicht 11.05.2022 19:15:07
- Zuletzt bearbeitet 21.11.2024 07:02:45
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php.
CVE-2022-27420
- EPSS 0.2%
- Veröffentlicht 04.05.2022 03:15:07
- Zuletzt bearbeitet 21.11.2024 06:55:42
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.
CVE-2022-27413
- EPSS 12.02%
- Veröffentlicht 03.05.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:55:41
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php.
CVE-2022-27299
- EPSS 0.27%
- Veröffentlicht 26.04.2022 14:15:40
- Zuletzt bearbeitet 21.11.2024 06:55:34
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php.