Auto Generated CVE annotations [Fri Sep 16 10:04:09 UTC 2022] 🤖

patch-1
GitHub Action 2022-09-16 10:04:09 +00:00
parent b98179c18c
commit e029635f69
1 changed files with 4 additions and 1 deletions

View File

@ -3,7 +3,7 @@ id: CVE-2022-38637
info:
name: Hospital Management System v1.0 - SQL Injection
author: arafatansari
severity: high
severity: critical
description: |
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/user-login.php.
reference:
@ -11,7 +11,10 @@ info:
- https://nvd.nist.gov/vuln/detail/CVE-2022-38637
- https://owasp.org/www-community/attacks/SQL_Injection
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2022-38637
cwe-id: CWE-89
metadata:
shodan-query: http.html:"Hospital Management System"
verified: "true"