CVE-2023-31498
- EPSS 9.12%
- Veröffentlicht 11.05.2023 11:15:09
- Zuletzt bearbeitet 27.01.2025 18:15:34
A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code and access sensitive information via the session token parameter.
CVE-2021-35388
- EPSS 0.55%
- Veröffentlicht 28.10.2022 15:15:13
- Zuletzt bearbeitet 07.05.2025 17:15:53
Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php.
CVE-2021-35387
- EPSS 0.74%
- Veröffentlicht 28.10.2022 15:15:12
- Zuletzt bearbeitet 07.05.2025 17:15:52
Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.
CVE-2022-42206
- EPSS 0.21%
- Veröffentlicht 21.10.2022 13:15:09
- Zuletzt bearbeitet 08.05.2025 15:15:47
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via doctor/view-patient.php, admin/view-patient.php, and view-medhistory.php.
CVE-2022-42205
- EPSS 0.21%
- Veröffentlicht 21.10.2022 13:15:09
- Zuletzt bearbeitet 08.05.2025 15:15:47
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via add-patient.php.
CVE-2022-24226
- EPSS 0.55%
- Veröffentlicht 15.02.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:50:00
Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.php.
CVE-2022-24646
- EPSS 0.36%
- Veröffentlicht 10.02.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:50:47
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.
CVE-2022-24263
- EPSS 2.31%
- Veröffentlicht 31.01.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:50:04
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.
CVE-2021-39411
- EPSS 1.67%
- Veröffentlicht 05.11.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:19:29
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searchdata parameter in (a) doctor/search.php and (b) admin/patient-search.php, and the (2) fromdate and (3) todate parameters in admin...
CVE-2020-22176
- EPSS 1.29%
- Veröffentlicht 22.06.2021 15:15:16
- Zuletzt bearbeitet 21.11.2024 05:13:09
PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information.