← Back

Hospital Management System

hospital_management_system

Vendor: Phpgurukul • 62 CVEs

CVEs (62)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Feb 15, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.php.
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Feb 10, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Jan 31, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Nov 5, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searchdata parameter in (a) doctor/search.php and (b) admin/patient-search.php, and the (2) fromdate and...Show more
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searchdata parameter in (a) doctor/search.php and (b) admin/patient-search.php, and the (2) fromdate and (3) todate parameters in admin/betweendates-detailsreports.php.Show less
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information.
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive i...Show more
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.Show less
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\registration.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\appointment-history.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Jun 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php. Remote registered users can exploit the vulnerability to obtain user cookie dat...Show more
PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php. Remote registered users can exploit the vulnerability to obtain user cookie data.Show less
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\forgot-password.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Jan 7, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history...Show more
PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.Show less
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Oct 8, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.
1Phpgurukul
1Hospital Management System
Nov 21, 2024
Jan 14, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or Doctorspecialization parameter.