Medium severity6.3NVD Advisory· Published Jul 21, 2023· Updated Jun 17, 2026
CVE-2023-3810
CVE-2023-3810
Description
A vulnerability was found in Hospital Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file patientappointment.php. The manipulation of the argument loginid/password/mobileno/appointmentdate/appointmenttime/patiente/dob/doct/city leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235078 is the identifier assigned to this vulnerability.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: = 1.0
Patches
Vulnerability mechanics
References
3- github.com/GZRsecurity/Cve-System/blob/main/Hospital%20Management%20System%20patientappointment.php%20has%20Sqlinjection.pdfnvdExploitThird Party Advisory
- vuldb.comnvdPermissions RequiredThird Party Advisory
- vuldb.comnvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.