code-projects Patient Record Management System
cpe:2.3:a:code-projects:patient_record_management_system:*:*:*:*:*:*:*
- 1.0
A critical SQL injection vulnerability has been identified in the Code-Projects Patient Record Management System version 1.0. The issue resides in the file 'xray_print.php', where the 'itr_no' parameter is manipulated, allowing for remote exploitation. This vulnerability enables attackers to execute arbitrary SQL commands, potentially leading to unauthorized access or modification of database information.
Exploitation of this vulnerability allows for arbitrary SQL command execution, which could be used to manipulate the database, extract sensitive information, or potentially escalate privileges within the application.
To reproduce this vulnerability, send a request to 'xray_print.php' with a crafted 'itr_no' parameter that includes SQL injection payloads. The lack of proper input sanitization will allow the injected SQL code to be executed by the database, demonstrating the vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.