cbcvebase.

Phpgurukul Hospital Management System vulnerabilities

69 known vulnerabilities affecting phpgurukul/hospital_management_system.

Total CVEs
69
CISA KEV
0
Public exploits
5
Exploited in wild
1
Severity breakdown
CRITICAL15HIGH26MEDIUM27LOW1

Vulnerabilities

Page 4 of 4
CVE-2024-10806P4MEDIUMCVSS 4.8v4.02024-11-05
CVE-2024-10806 [MEDIUM] CWE-74 CVE-2024-10806: A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as prob A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulnerability affects unknown code of the file betweendates-detailsreports.php. The manipulation of the argument fromdate/todate leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the pu
nvd
CVE-2024-46239P4MEDIUMCVSS 5.9v4.02024-10-21
CVE-2024-46239 [MEDIUM] CWE-79 CVE-2024-46239: Multiple cross-site scripting vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via Multiple cross-site scripting vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /doctor/edit-profile.php and adminremark parameter in /admin/query-details.php.
nvd
CVE-2024-46238P4MEDIUMCVSS 5.9v4.02024-10-21
CVE-2024-46238 [MEDIUM] CWE-79 CVE-2024-46238: Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4 Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php
nvd
CVE-2022-42205P4MEDIUMCVSS 5.4v4.02022-10-21
CVE-2022-42205 [MEDIUM] CWE-79 CVE-2022-42205: PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via a PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via add-patient.php.
nvd
CVE-2021-35388P4MEDIUMCVSS 5.4v4.02022-10-28
CVE-2021-35388 [MEDIUM] CWE-79 CVE-2021-35388: Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php.
nvd
CVE-2024-56990P4MEDIUMCVSS 4.5v4.02025-01-21
CVE-2024-56990 [MEDIUM] CWE-79 CVE-2024-56990: PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /view-medhi PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /view-medhistory.php and /admin/view-patient.php.
nvd
CVE-2024-56998P4MEDIUMCVSS 4.2v4.02025-01-21
CVE-2024-56998 [MEDIUM] CWE-79 CVE-2024-56998: PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /edit-profi PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /edit-profile.php via the parameter $address.
nvd
CVE-2024-56997P4MEDIUMCVSS 4.2v4.02025-01-21
CVE-2024-56997 [MEDIUM] CWE-79 CVE-2024-56997: PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /doctor/ind PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /doctor/index.php via the 'Email' parameter.
nvd
CVE-2022-46498P4LOWCVSS 2.7v1.02024-03-07
CVE-2022-46498 [LOW] CWE-89 CVE-2022-46498: Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_n Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php.
nvd