Clinic Pro SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in Clinic Pro versions through 4. This vulnerability allows authenticated attackers to manipulate database queries by injecting SQL code into the 'month' parameter. Exploitation can be achieved by sending POST requests to the 'monthly_expense_overview' endpoint, using crafted month values that leverage boolean-based blind, time-based blind, or error-based SQL injection techniques to extract sensitive information from the database.

Impact

Exploitation of this vulnerability allows for unauthorized database access and information retrieval, potentially including sensitive data.

Reproduction

To reproduce this vulnerability, log in as an authenticated user and send a POST request to the 'monthly_expense_overview' endpoint. Include a crafted 'month' parameter value that exploits the SQL injection vulnerability. This can be done using boolean-based blind, time-based blind, or error-based SQL injection techniques.

Added: Mar 12, 2026, 4:37 PM
Updated: Mar 12, 2026, 4:37 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
3.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.