RULE(RULE ID:337947)

Rule General Information
Release Date: 2024-04-23
Rule Name: Hongfan iOffice SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Hongfan iOffice.net, which was originally designed to meet the needs of hospital administrative offices (traditional OA), has now integrated management standards from health authorities and numerous industry-specific applications. It is currently the only software that focuses on solving hospital comprehensive business management and is the hospital comprehensive business management platform that best fits the characteristics of the hospital industry. It is the hospital comprehensive business management software with the most successful cases. There is an SQL injection vulnerability at the Redfan iOffice.net udfmR.asmx interface, which allows unauthorized attackers to obtain sensitive database information and credentials, ultimately leading to server crashes. This feature is used to detect traffic suspected of this vulnerability, and there is a certain possibility of false positives. It needs to be judged based on specific circumstances.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.