← Back

Hospital Management System

hospital_management_system

Vendor: Phpgurukul • 62 CVEs

CVEs (62)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phpgurukul
1Hospital Management System
Feb 23, 2026
Feb 18, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor Manag...Show more
PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor Management) by manually browsing to the /admin/ directory after authentication. This allows any self-registered user to takeover the application, view confidential logs, and modify system data.Show less
1Phpgurukul
1Hospital Management System
Feb 26, 2026
Feb 18, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vulnerability. The application fails to verify that the requested 'viewid' parameter belongs...Show more
The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vulnerability. The application fails to verify that the requested 'viewid' parameter belongs to the currently authenticated patient. This allows a user to access the confidential medical records of other patients by iterating the 'viewid' integer.Show less
1Phpgurukul
1Hospital Management System
Feb 23, 2026
Feb 18, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fails to enforce CSRF token validation on the add-doctor.php endpoint. Thi...Show more
PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fails to enforce CSRF token validation on the add-doctor.php endpoint. This allows remote attackers to create arbitrary Doctor accounts (privileged users) by tricking an authenticated administrator into visiting a malicious page.Show less
1Phpgurukul
1Hospital Management System
Apr 29, 2026
Feb 8, 2026
2.0 LOW· v4
7.2 HIGH· v3
5.8 MEDIUM· v2
A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. This manipulation of the argument ID causes sql injection. The attack can...Show more
A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.Show less
1Phpgurukul
1Hospital Management System
Apr 29, 2026
Feb 8, 2026
2.0 LOW· v4
7.2 HIGH· v3
5.8 MEDIUM· v2
A security vulnerability has been detected in PHPGurukul Hospital Management System 4.0. The affected element is an unknown function of the file /hms/admin/manage-doctors.php. Such manipulation of the argument ID leads t...Show more
A security vulnerability has been detected in PHPGurukul Hospital Management System 4.0. The affected element is an unknown function of the file /hms/admin/manage-doctors.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.Show less
1Phpgurukul
1Hospital Management System
Apr 29, 2026
Jan 28, 2026
2.1 LOW· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/adminviews.py of the component Admin Dashboard...Show more
A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/adminviews.py of the component Admin Dashboard Page. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.Show less
1Phpgurukul
1Hospital Management System
Apr 6, 2026
Aug 25, 2025
N/A· v4
8.5 HIGH· v3
N/A· v2
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in about-us.php via the pagetitle parameter.
1Phpgurukul
1Hospital Management System
Apr 6, 2026
Aug 25, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in contact.php via the pagetitle parameter.
1Phpgurukul
1Hospital Management System
Apr 6, 2026
Aug 25, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter.
1Phpgurukul
1Hospital Management System
Apr 6, 2026
Aug 25, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in add-doctor.php via the docname parameter.
1Phpgurukul
1Hospital Management System
Apr 29, 2026
Jul 14, 2025
5.5 MEDIUM· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /user-login.php. The manipulation of the ar...Show more
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /user-login.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Phpgurukul
1Hospital Management System
Apr 29, 2026
Jul 8, 2025
5.5 MEDIUM· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file view-medhistory.php. The manipulation of th...Show more
A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file view-medhistory.php. The manipulation of the argument viewid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Phpgurukul
1Hospital Management System
May 29, 2025
May 23, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor/edit-profile.php file
1Phpgurukul
1Hospital Management System
Apr 9, 2025
Jan 21, 2025
N/A· v4
4.5 MEDIUM· v3
N/A· v2
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /view-medhistory.php and /admin/view-patient.php.
1Phpgurukul
1Hospital Management System
Apr 9, 2025
Jan 21, 2025
N/A· v4
4.2 MEDIUM· v3
N/A· v2
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /edit-profile.php via the parameter $address.
1Phpgurukul
1Hospital Management System
Apr 9, 2025
Jan 21, 2025
N/A· v4
4.2 MEDIUM· v3
N/A· v2
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /doctor/index.php via the 'Email' parameter.
1Phpgurukul
1Hospital Management System
Dec 4, 2024
Nov 26, 2024
5.3 MEDIUM· v4
5.4 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /backend/admin/his_admin_register_patient.p...Show more
A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /backend/admin/his_admin_register_patient.php of the component Add Patient Details Page. The manipulation of the argument pat_fname/pat_ailment/pat_lname/pat_age/pat_dob/pat_number/pat_phone/pat_type/pat_addr leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Phpgurukul
1Hospital Management System
Mar 31, 2025
Oct 21, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Multiple cross-site scripting vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /doctor/edit-profile.php and adminremark parameter in /admin/query-details.php.
1Phpgurukul
1Hospital Management System
Mar 31, 2025
Oct 21, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php
1Phpgurukul
1Hospital Management System
Oct 22, 2024
Oct 9, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.