VendorsPHPGurukulhospital_management_system4.0
Vulnerabilities

PHPGurukul Hospital Management System 4.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

48CVEs
CVE-2022-42206
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via doctor/view-patient.php, admin/view-patient.php, and view-medhistory.php.
Published 2022-10-21 · Modified
5.4EPSS 0.005
CVE-2021-35388
Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php.
Published 2022-10-28 · Modified
5.4EPSS 0.004
CVE-2024-46237
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.
Published 2024-10-09 · Modified
5.4EPSS 0.003
CVE-2020-26630
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an admin.
Published 2024-01-10 · Modified
4.9EPSS 0.007
CVE-2020-26627
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under the 'Contact Us Queries -> Unread Query' tab.
Published 2024-01-10 · Modified
4.9EPSS 0.007
CVE-2024-56990
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /view-medhistory.php and /admin/view-patient.php.
Published 2025-01-21 · Analyzed
4.5EPSS 0.004
CVE-2024-56998
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /edit-profile.php via the parameter $address.
Published 2025-01-21 · Analyzed
4.2EPSS 0.002
CVE-2024-56997
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /doctor/index.php via the 'Email' parameter.
Published 2025-01-21 · Analyzed
4.2EPSS 0.002
← Prev2 / 2