CVE-2024-10987

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Nov 8, 2024
Updated: Nov 13, 2024
CWE ID 89
CWE ID 74

Summary

CVE-2024-10987 is a critical vulnerability affecting the code-projects E-Health Care System 1.0. An unknown functionality in the file /Doctor/user_appointment.php contains a sql injection vulnerability. Maliciously crafted inputs to the schedule_id/schedule_date/schedule_day/start_time/end_time/booking parameters can manipulate SQL queries, leading to unauthorized data access or modification. The attack can be launched remotely, and the exploit has been disclosed to the public, increasing the risk of widespread exploitation. Users are strongly encouraged to apply the available patch or upgrade to a secure version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share