CVE-2024-10740 | code-projects E-Health Care System up to 1.0 consulting_detail.php consulting_id sql injection
A vulnerability, which was classified as critical, was found in code-projects E-Health Care System up to 1.0. This affects an unknown part of the file /Admin/consulting_detail.php. The manipulation of the argument consulting_id with the input 11%27%20union%20select%20group_concat(table_name),database(),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23%20from%20information_schema.tables%20where%20table_schema%20=%20database();--+ as part of String leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-10740. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.