"product_name":"KiviCare – Clinic & Patient Management System (EHR)",
"version":{
"version_data":[
{
"version_affected":"<",
"version_name":"2.3.9",
"version_value":"2.3.9"
}
]
}
}
]
}
}
]
}
},
"description":{
"description_data":[
{
"lang":"eng",
"value":"The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users"