PoC Index

CVE-2018-18705

CRITICAL 9.8EPSS 2.0%

PhpTpoint hospital management system suffers from multiple SQL injection vulnerabilities via the index.php user parameter associated with LOGIN.php, or the rno parameter to ALIST.php, DUNDEL.php, PDEL.php, or PUNDEL.php.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.97% chance of exploitation in the next 30 days, 79th percentile
Published
2018-10-27
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related