在 UNION HospitalManagementSystem(版本直至 9ef91ed6007314b6473110ed699dff76d158f61d)中发现了一个漏洞。受影响的为 patient_info.php 文件中的一个未知函数。通过操纵参数 patient_id 可导致 SQL 注入漏洞。该漏洞可被远程利用。相关利用代码已公开并可被使用。该产品采用滚动发布策略以支持持续交付,因此无法准确指定受影响版本或已修复版本的具体版本号。项目方已通过问题报告较早获悉此漏洞,但截至目前尚未作出回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| UNION | HospitalManagementSystem | 9ef91ed6007314b6473110ed699dff76d158f61d |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| UNION | HospitalManagementSystem | 9ef91ed6007314b6473110ed699dff76d158f61d |
cpe:2.3:a:union:hospitalmanagementsystem:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet