Le-show medical practice management system from Le-yan has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
| Software | From | Fixed in |
|---|---|---|
| le-show / le-yan | - | 3.2.25.x |