1 results (0.002 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

A vulnerability, which was classified as critical, has been found in SourceCodester Medicine Tracking System 1.0. This issue affects some unknown processing of the file /classes/Master.php? f=save_medicine. The manipulation of the argument id/name/description leads to sql injection. The attack may be initiated remotely. • https://medium.com/@2839549219ljk/medicine-tracking-system-sql-injection-7b0dde3a82a4 https://vuldb.com/?ctiid.249095 https://vuldb.com/?id.249095 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •