VendorsHospital Management System Projecthospital_management_system1.0
Vulnerabilities

Hospital Management System Project Hospital Management System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2022-30011
In HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability.
Published 2022-05-16 · Modified
9.8EPSS 0.187
CVE-2022-32094
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.php.
Published 2022-07-01 · Modified
9.8EPSS 0.077
CVE-2022-38637
Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page.
Published 2022-09-13 · Modified
9.8EPSS 0.061
CVE-2022-27413
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php.
Published 2022-05-03 · Modified
9.8EPSS 0.030
CVE-2021-44095
A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote attacker to compromise Application SQL database.
Published 2022-05-31 · Modified
9.8EPSS 0.022
CVE-2022-24136
Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php. To exploit, an attacker can upload any PHP file, and then execute it.
Published 2022-03-31 · Modified
9.8EPSS 0.019
CVE-2022-30448
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php.
Published 2022-05-11 · Modified
9.8EPSS 0.019
CVE-2022-30449
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php.
Published 2022-05-11 · Modified
9.8EPSS 0.016
CVE-2022-25490
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.
Published 2022-03-15 · Modified
9.8EPSS 0.016
CVE-2022-25492
HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php.
Published 2022-03-15 · Modified
9.8EPSS 0.016
CVE-2022-32095
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at orders.php.
Published 2022-07-01 · Modified
9.8EPSS 0.016
CVE-2022-30516
In Hospital-Management-System v1.0, the editid parameter in the doctor.php page is vulnerable to SQL injection attacks.
Published 2022-05-26 · Modified
9.8EPSS 0.016
CVE-2022-28929
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the delid parameter at viewtreatmentrecord.php.
Published 2022-05-15 · Modified
9.8EPSS 0.016
CVE-2022-27299
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php.
Published 2022-04-26 · Modified
9.8EPSS 0.016
CVE-2022-25403
HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php.
Published 2022-02-23 · Modified
9.8EPSS 0.016
CVE-2022-32093
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at adminlogin.php.
Published 2022-07-01 · Modified
9.8EPSS 0.016
CVE-2022-27420
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.
Published 2022-05-04 · Modified
9.8EPSS 0.014
CVE-2023-4176
SourceCodester Hospital Management System appointmentapproval.php sql injection
Published 2023-08-06 · Modified
9.8EPSS 0.008
CVE-2023-3811
Hospital Management System patientprofile.php sql injection
Published 2023-07-21 · Modified
9.8EPSS 0.007
CVE-2023-3809
Hospital Management System patient.php sql injection
Published 2023-07-21 · Modified
9.8EPSS 0.007
CVE-2023-3810
Hospital Management System patientappointment.php sql injection
Published 2023-07-21 · Modified
9.8EPSS 0.007
CVE-2022-25402
An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files.
Published 2022-02-23 · Modified
9.1EPSS 0.016
CVE-2022-26546
Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive information and obtain the admin password.
Published 2022-03-31 · Modified
9.1EPSS 0.014
CVE-2023-3808
Hospital Management System patientforgotpassword.php sql injection
Published 2023-07-21 · Modified
8.8EPSS 0.007
CVE-2024-11674
CodeAstro Hospital Management System his_doc_update-account.php unrestricted upload
Published 2024-11-25 · Analyzed
8.8EPSS 0.006
CVE-2022-46093
Hospital Management System v1.0 is vulnerable to SQL Injection. Attackers can gain administrator privileges without the need for a password.
Published 2023-01-13 · Modified
8.2EPSS 0.007
CVE-2022-30012
In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple parameters, and database information can be obtained through injection.
Published 2022-05-16 · Modified
7.5EPSS 0.017
CVE-2022-25491
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php.
Published 2022-03-15 · Modified
7.5EPSS 0.015
CVE-2022-34590
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php.
Published 2022-07-20 · Modified
7.2EPSS 0.046
CVE-2022-25493
HMS v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via treatmentrecord.php.
Published 2022-03-15 · Modified
6.1EPSS 0.008
CVE-2023-34651
PHPgurukl Hospital Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).
Published 2023-06-28 · Modified
6.1EPSS 0.005
CVE-2022-25408
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpassword parameter at /admin-panel1.php.
Published 2022-02-28 · Modified
5.4EPSS 0.005
CVE-2022-25407
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doctor parameter at /admin-panel1.php.
Published 2022-02-28 · Modified
5.4EPSS 0.005
CVE-2022-25409
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.
Published 2022-02-28 · Modified
5.4EPSS 0.005
CVE-2024-11678
CodeAstro Hospital Management System his_doc_register_patient.php cross site scripting
Published 2024-11-26 · Analyzed
5.4EPSS 0.005
CVE-2024-11676
CodeAstro Hospital Management System Add Laboratory Equipment Page his_admin_add_lab_equipment.php cross site scripting
Published 2024-11-26 · Analyzed
5.4EPSS 0.005
CVE-2024-11677
CodeAstro Hospital Management System Add Vendor Details Page his_admin_add_vendor.php cross site scripting
Published 2024-11-26 · Analyzed
5.4EPSS 0.005