CVE-2020-24862

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
02/06/2021
Last modified:
09/06/2021

Description

The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind SQL injection via the /medical/inventories.php path which allows attackers to retrieve all databases.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pharmacy_medical_store_and_sale_point_project:pharmacy_medical_store_and_sale_point:1.0:*:*:*:*:*:*:*