messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter.
References
Link Resource
https://cliniccases.com Vendor Advisory
https://github.com/judsonmitchell/ClinicCases/releases Release Notes Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-09-07T19:13:15

Updated: 2021-09-07T19:13:15

Reserved: 2021-08-15T00:00:00


Link: CVE-2021-38706

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-09-07T20:15:08.093

Modified: 2021-09-10T19:56:32.163


Link: CVE-2021-38706

JSON object: View

cve-icon Redhat Information

No data.

CWE