Codezips Pharmacy Management System是Codezips的一个药房管理系统。 Codezips Pharmacy Management System 1.0版本存在SQL注入漏洞,该漏洞源于文件produc/update.php的参数id会导致SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Codezips | Pharmacy Management System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-9813 | 7.3 HIGH | Codezips Pharmacy Management System register.php sql injection |
| CVE-2024-9794 | 6.3 MEDIUM | Codezips Online Shopping Portal update-image1.php unrestricted upload |
| CVE-2024-9816 | 4.7 MEDIUM | Codezips Tourist Management System change-image.php unrestricted upload |
| CVE-2024-9815 | 4.7 MEDIUM | Codezips Tourist Management System create-package.php unrestricted upload |
No comments yet