Vendorskishan0725hospital_management_system4.0
Vulnerabilities

kishan0725 Hospital Management System 4.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2023-43958
An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthenticated attacker to upload any file to the server and execute arbitrary code.
Published 2025-04-22 · Analyzed
9.8EPSS 0.012
CVE-2023-41525
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.
Published 2025-08-07 · Analyzed
9.8EPSS 0.004
CVE-2023-41526
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters.
Published 2025-08-07 · Analyzed
9.8EPSS 0.004
CVE-2023-41527
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.
Published 2025-08-07 · Analyzed
9.8EPSS 0.004
CVE-2023-41528
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters.
Published 2025-08-07 · Analyzed
9.8EPSS 0.004
CVE-2023-41530
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.
Published 2025-08-07 · Analyzed
9.8EPSS 0.004
CVE-2023-41531
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the username1 and password2 parameters.
Published 2025-08-07 · Analyzed
8.8EPSS 0.003
CVE-2023-41532
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter in doctorsearch.php.
Published 2025-08-07 · Analyzed
8.8EPSS 0.003
CVE-2025-63513
kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality.
Published 2025-11-18 · Analyzed
6.5EPSS 0.003
CVE-2025-63512
kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleting doctor logic. The application fails to properly sanitize or parameterize user-supplied input from the demail parameter before incorporating it directly into a dynamic SQL query.
Published 2025-11-18 · Analyzed
6.5EPSS 0.002
CVE-2023-40992
Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the password2 parameter.
Published 2025-08-07 · Analyzed
6.5EPSS 0.002
CVE-2023-41529
Hospital Management System v4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in func2.php via the fname and lname parameters.
Published 2025-08-07 · Analyzed
6.1EPSS 0.002