VendorsHospital Management System Projecthospital_management_systemany version
Vulnerabilities

Hospital Management System Project Hospital Management System any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2021-38754
SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php.
Published 2021-08-16 · Modified
9.8EPSS 0.018
CVE-2022-48120
SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on March 13, 2021), allows attackers to execute arbitrary commands via the contact and doctor parameters to /search.php.
Published 2023-01-20 · Modified
9.8EPSS 0.009
CVE-2023-43909
Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.
Published 2023-09-29 · Modified
9.1EPSS 0.007
CVE-2021-38757
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.
Published 2021-08-16 · Modified
6.1EPSS 0.009
CVE-2021-38756
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through prescribe.php.
Published 2021-08-16 · Modified
6.1EPSS 0.007
CVE-2021-38755
Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php.
Published 2021-08-16 · Modified
5.3EPSS 0.010