CVE-2024-12969

CVSS 2.0 Score 7.5 of 10 (high)

Details

Published Dec 26, 2024
Updated: Dec 27, 2024
CWE ID 74
CWE ID 89

Summary

CVE-2024-12969 is a newly disclosed critical vulnerability affecting the Hospital Management System 1.0 and its /admin/index.php component, specifically the Login functionality. This issue allows an attacker to execute SQL injection by manipulating the username/password argument, potentially gaining unauthorized access to sensitive data. The vulnerability can be exploited remotely, making it a significant risk for organizations using this software. The exploit for this vulnerability has been made public, increasing the urgency for affected organizations to apply patches or workarounds to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share