Home

Description

Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by manipulating the ck_config cookie parameter. Attackers can inject malicious SQL through the ck_config cookie in multiple endpoints including login.php, indexframe.php, and various module files to extract sensitive database information without authentication.

PUBLISHED Reserved 2026-06-04 | Published 2026-06-04 | Updated 2026-06-04 | Assigner VulnCheck




HIGH: 8.8CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
HIGH: 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Problem types

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

2.7
affected

Credits

Carlos Avila finder

References

www.exploit-db.com/exploits/46268 (ExploitDB-46268) exploit

www.vulncheck.com/...tion-system-sql-injection-via-ck-config (VulnCheck Advisory: Care2x 2.7 Hospital Information System SQL Injection via ck_config) third-party-advisory

cve.org (CVE-2019-25728)

nvd.nist.gov (CVE-2019-25728)

Download JSON