VendorsProjectworldshospital_management_system_in_phpall versions
Vulnerabilities

Projectworlds Hospital Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2021-43628
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.
Published 2021-12-22 · Modified
9.8EPSS 0.011
CVE-2021-43629
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.
Published 2021-12-22 · Modified
9.8EPSS 0.011
CVE-2021-43631
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php.
Published 2021-12-22 · Modified
9.8EPSS 0.011
CVE-2023-5004
Hospital-management-system-in-php 378c157 - Blind SQL Injection
Published 2023-09-28 · Modified
9.8EPSS 0.009
CVE-2023-5053
SQL Injection in hospital-management-system-in-php 378c157 in index.php
Published 2023-09-28 · Modified
9.8EPSS 0.009
CVE-2021-43630
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an authenticated malicious user can compromise the databases system and in some cases leverage this vulnerability to get remote code execution on the remote web server.
Published 2021-12-22 · Modified
8.8EPSS 0.020
CVE-2021-45852
An issue was discovered in Projectworlds Hospital Management System v1.0. Unauthorized malicious attackers can add patients without restriction via add_patient.php.
Published 2022-03-16 · Modified
5.3EPSS 0.007