Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2021-45852
Disclosure Date: March 16, 2022 (last updated February 23, 2025)
An issue was discovered in Projectworlds Hospital Management System v1.0. Unauthorized malicious attackers can add patients without restriction via add_patient.php.
0
Attacker Value
Unknown
CVE-2021-43631
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php.
0
Attacker Value
Unknown
CVE-2021-43630
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an authenticated malicious user can compromise the databases system and in some cases leverage this vulnerability to get remote code execution on the remote web server.
0
Attacker Value
Unknown
CVE-2021-43629
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.
0
Attacker Value
Unknown
CVE-2021-43628
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.
0