### [CVE-2024-8080](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8080) ![](https://img.shields.io/static/v1?label=Product&message=Online%20Health%20Care%20System&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3D%201.0%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-89%20SQL%20Injection&color=brighgreen) ### Description A vulnerability classified as critical has been found in SourceCodester Online Health Care System 1.0. Affected is an unknown function of the file search.php. The manipulation of the argument f_name with the input 1%' or 1=1 ) UNION SELECT 1,2,3,4,5,database(),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23# as part of string leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. ### POC #### Reference - https://github.com/shang159/sqli-vul/blob/main/sql2.md #### Github No PoCs found on GitHub currently.