CVE-2024-10987
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-10987 is a critical vulnerability affecting the code-projects E-Health Care System 1.0. An unknown functionality in the file /Doctor/user_appointment.php contains a sql injection vulnerability. Maliciously crafted inputs to the schedule_id/schedule_date/schedule_day/start_time/end_time/booking parameters can manipulate SQL queries, leading to unauthorized data access or modification. The attack can be launched remotely, and the exploit has been disclosed to the public, increasing the risk of widespread exploitation. Users are strongly encouraged to apply the available patch or upgrade to a secure version as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.