Vendorsoretnom23clinic%5C's_patient_management_systemall versions
Vulnerabilities

oretnom23 Clinic's Patient Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

27CVEs
CVE-2022-40471
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php
Published 2022-10-31 · Modified
9.8EPSS 0.218
CVE-2022-36270
Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php.
Published 2022-08-10 · Modified
9.8EPSS 0.014
CVE-2022-36750
Clinic's Patient Management System v1.0 is vulnerable to SQL injection via /pms/update_user.php?id=.
Published 2022-08-10 · Modified
9.8EPSS 0.010
CVE-2022-2298
SourceCodester Clinics Patient Management System Login Page index.php sql injection
Published 2022-07-12 · Modified
9.8EPSS 0.009
CVE-2022-36242
Clinic's Patient Management System v1.0 is vulnerable to SQL Injection via /pms/update_medicine.php?id=.
Published 2022-08-16 · Modified
9.8EPSS 0.009
CVE-2022-3120
SourceCodester Clinics Patient Management System Login index.php sql injection
Published 2022-09-05 · Modified
9.8EPSS 0.008
CVE-2022-3122
SourceCodester Clinics Patient Management System medicine_details.php sql injection
Published 2022-09-05 · Modified
9.8EPSS 0.008
CVE-2022-36609
Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pms/update_patient.php.
Published 2022-09-02 · Modified
9.8EPSS 0.007
CVE-2024-8565
SourceCodesters Clinics Patient Management System print_diseases.php sql injection
Published 2024-09-07 · Analyzed
9.8EPSS 0.007
CVE-2024-7494
SourceCodester Clinics Patient Management System new_prescription.php sql injection
Published 2024-08-05 · Analyzed
9.8EPSS 0.006
CVE-2024-7454
SourceCodester Clinics Patient Management System patients.php patient_name sql injection
Published 2024-08-04 · Analyzed
9.8EPSS 0.005
CVE-2022-2297
SourceCodester Clinics Patient Management System unrestricted upload
Published 2022-07-12 · Modified
8.8EPSS 0.033
CVE-2023-1035
SourceCodester Clinics Patient Management System update_user.php sql injection
Published 2023-02-25 · Analyzed
8.8EPSS 0.007
CVE-2024-7930
SourceCodester Clinics Patient Management System get_packings.php sql injection
Published 2024-08-19 · Analyzed
8.8EPSS 0.006
CVE-2024-7753
SourceCodester Clinics Patient Management System user_images direct request
Published 2024-08-14 · Analyzed
7.5EPSS 0.009
CVE-2024-7751
SourceCodester Clinics Patient Management System update_medicine.php sql injection
Published 2024-08-13 · Analyzed
7.5EPSS 0.005
CVE-2024-7754
SourceCodester Clinics Patient Management System check_medicine_name.php sql injection
Published 2024-08-14 · Analyzed
7.5EPSS 0.005
CVE-2024-7750
SourceCodester Clinics Patient Management System medicines.php sql injection
Published 2024-08-13 · Analyzed
7.5EPSS 0.005
CVE-2024-7841
SourceCodester Clinics Patient Management System check_user_name.php sql injection
Published 2024-08-15 · Analyzed
7.5EPSS 0.005
CVE-2024-6968
SourceCodester Clinics Patient Management System print_patients_visits.php sql injection
Published 2024-07-22 · Modified
7.5EPSS 0.004
CVE-2024-6969
SourceCodester Clinics Patient Management System get_patient_history.php sql injection
Published 2024-07-22 · Modified
7.5EPSS 0.004
CVE-2024-8555
SourceCodester Clinics Patient Management System congratulations.php redirect
Published 2024-09-07 · Analyzed
6.9EPSS 0.006
CVE-2024-7645
SourceCodester Clinics Patient Management System User Page users.php cross-site request forgery
Published 2024-08-09 · Analyzed
6.9EPSS 0.004
CVE-2022-36251
Clinic's Patient Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via patients.php.
Published 2022-08-22 · Modified
6.1EPSS 0.006
CVE-2024-7752
SourceCodester Clinics Patient Management System update_medicine.php cross site scripting
Published 2024-08-13 · Analyzed
6.1EPSS 0.005
CVE-2024-8554
SourceCodester Clinics Patient Management System users.php cross site scripting
Published 2024-09-07 · Analyzed
5.4EPSS 0.005
CVE-2022-35117
Clinic's Patient Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via update_medicine_details.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Packing text box under the Update Medical Details module.
Published 2022-08-17 · Modified
4.8EPSS 0.006