CVE-2022-33880
Published on: Not Yet Published
Last Modified on: 10/06/2022 08:22:00 PM UTC
Certain versions of Hospital Management System Mini-project from Hospital Management System Mini-project Project contain the following vulnerability:
hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the type parameter.
- CVE-2022-33880 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Vulnerability/BUG - Unauthenticated bind boolean based sql injection via type parameter on hms-staff.php page · Issue #7 · projectworldsofficial/hospital-management-system-in-php · GitHub | github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Exploit/POC from Github
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file i…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Hospital Management System Mini-project Project | Hospital Management System Mini-project | All | All | All | All |
- cpe:2.3:a:hospital_management_system_mini-project_project:hospital_management_system_mini-project:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-33880 : hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows S… twitter.com/i/web/status/1… | 2022-09-29 19:06:52 |
![]() |
Potentially Critical CVE Detected! CVE-2022-33880 hms-staff.php in Projectworlds Hospital Management System Mini-Pr… twitter.com/i/web/status/1… | 2022-09-29 19:55:55 |
![]() |
Php - CVE-2022-33880: github.com/projectworldso… | 2022-09-29 22:00:04 |
![]() |
CVE-2022-33880 | 2022-09-29 20:38:44 |