CVE-2024-10995

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Nov 8, 2024
Updated: Nov 13, 2024
CWE ID 74
CWE ID 89

Summary

CVE-2024-10995 is a critical vulnerability affecting the Codezips Hospital Appointment System 1.0. This issue lies within an unspecified functionality of the file /removeDoctorResult.php. An attacker can exploit this SQL injection vulnerability by manipulating the Name argument. The exploit can be launched remotely, and the details of the attack have been disclosed to the public, increasing the risk of widespread exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share