Phpgurukul Hospital Management System vulnerabilities

69 known vulnerabilities affecting phpgurukul/hospital_management_system.

Total CVEs
69
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH22MEDIUM35LOW1

Vulnerabilities

Page 4 of 4
CVE-2020-22165HIGHCVSS 7.5PoCv4.02021-06-22
CVE-2020-22165 [HIGH] CWE-89 CVE-2020-22165: PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-log PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
nvd
CVE-2020-22168HIGHCVSS 7.5v4.02021-06-22
CVE-2020-22168 [HIGH] CWE-89 CVE-2020-22168: PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-e PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
nvd
CVE-2020-22172HIGHCVSS 7.5v4.02021-06-22
CVE-2020-22172 [HIGH] CWE-89 CVE-2020-22172: PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doct PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
nvd
CVE-2020-22167MEDIUMCVSS 5.4v4.02021-06-22
CVE-2020-22167 [MEDIUM] CWE-79 CVE-2020-22167: PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerabilit PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php. Remote registered users can exploit the vulnerability to obtain user cookie data.
nvd
CVE-2020-35745HIGHCVSS 8.8v4.02021-01-07
CVE-2020-35745 [HIGH] CWE-862 CVE-2020-35745: PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.
nvd
CVE-2020-25271MEDIUMCVSS 5.4v4.02020-10-08
CVE-2020-25271 [MEDIUM] CWE-79 CVE-2020-25271: PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/sea PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.
nvd
CVE-2020-5193MEDIUMCVSS 6.1v4.02020-01-14
CVE-2020-5193 [MEDIUM] CWE-79 CVE-2020-5193: PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilitie PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or Doctorspecialization parameter.
nvd
CVE-2020-5192HIGHCVSS 8.8PoCv4.02020-01-06
CVE-2020-5192 [HIGH] CWE-89 CVE-2020-5192: PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilitie PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.
nvd
CVE-2020-5191MEDIUMCVSS 6.1PoCv4.02020-01-06
CVE-2020-5191 [MEDIUM] CWE-79 CVE-2020-5191: PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabiliti PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.
nvd