WordPress KiviCare是WordPress基金会的一款医疗诊所管理组件。 WordPress KiviCare 4.5.1及之前版本存在SQL注入漏洞,该漏洞源于对searchTerm参数未充分转义且现有SQL查询准备不足,可能导致已认证攻击者向现有查询追加额外SQL查询,从而提取数据库中的敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| iqonicdesign | KiviCare – Clinic & Patient Management System (EHR) | ≤ 4.5.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| iqonicdesign | KiviCare – Clinic & Patient Management System (EHR) | 0 ~ 4.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet