CVE-2024-56997
- EPSS 0.08%
- Veröffentlicht 21.01.2025 15:15:13
- Zuletzt bearbeitet 09.04.2025 18:34:09
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /doctor/index.php via the 'Email' parameter.
CVE-2024-11675
- EPSS 0.16%
- Veröffentlicht 26.11.2024 01:15:04
- Zuletzt bearbeitet 04.12.2024 20:15:39
A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /backend/admin/his_admin_register_patient.php of the component Add Patien...
CVE-2024-46239
- EPSS 0.11%
- Veröffentlicht 21.10.2024 19:15:03
- Zuletzt bearbeitet 31.03.2025 17:52:58
Multiple cross-site scripting vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /doctor/edit-profile.php and adminremark parameter in /admin/query-details.php.
CVE-2024-46238
- EPSS 0.1%
- Veröffentlicht 21.10.2024 19:15:03
- Zuletzt bearbeitet 31.03.2025 17:52:15
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php
CVE-2024-46237
- EPSS 0.15%
- Veröffentlicht 09.10.2024 14:15:07
- Zuletzt bearbeitet 22.10.2024 18:35:05
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.
CVE-2022-46499
- EPSS 0.16%
- Veröffentlicht 07.03.2024 09:15:38
- Zuletzt bearbeitet 28.03.2025 18:06:22
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php.
CVE-2022-46498
- EPSS 0.06%
- Veröffentlicht 07.03.2024 09:15:38
- Zuletzt bearbeitet 28.03.2025 18:06:16
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php.
CVE-2022-46497
- EPSS 0.13%
- Veröffentlicht 07.03.2024 09:15:37
- Zuletzt bearbeitet 28.03.2025 18:06:06
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_view_single_patien.php.
CVE-2020-26630
- EPSS 0.09%
- Veröffentlicht 10.01.2024 09:15:43
- Zuletzt bearbeitet 22.05.2025 18:15:23
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging...
CVE-2020-26629
- EPSS 0.72%
- Veröffentlicht 10.01.2024 09:15:43
- Zuletzt bearbeitet 09.05.2025 19:15:50
A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the server.