CVE-2025-69949
- EPSS 0.15%
- Veröffentlicht 29.07.2026 00:00:00
- Zuletzt bearbeitet 30.07.2026 14:16:45
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email.
CVE-2025-69945
- EPSS 0.14%
- Veröffentlicht 29.07.2026 00:00:00
- Zuletzt bearbeitet 30.07.2026 14:16:45
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.
CVE-2025-69944
- EPSS 0.17%
- Veröffentlicht 29.07.2026 00:00:00
- Zuletzt bearbeitet 04.08.2026 20:16:47
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter.
CVE-2025-69943
- EPSS 0.15%
- Veröffentlicht 29.07.2026 00:00:00
- Zuletzt bearbeitet 30.07.2026 15:16:23
kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.
CVE-2025-69942
- EPSS 0.14%
- Veröffentlicht 29.07.2026 00:00:00
- Zuletzt bearbeitet 30.07.2026 19:17:00
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.
CVE-2025-65340
- EPSS 0.14%
- Veröffentlicht 29.07.2026 00:00:00
- Zuletzt bearbeitet 30.07.2026 19:17:00
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.
CVE-2025-63514
- EPSS 0.2%
- Veröffentlicht 18.11.2025 00:00:00
- Zuletzt bearbeitet 20.11.2025 21:54:40
kishan0725 Hospital Management System has a Cross-Site Scripting (XSS) vulnerability in appsearch.php via the email parameter.
CVE-2025-63513
- EPSS 0.27%
- Veröffentlicht 18.11.2025 00:00:00
- Zuletzt bearbeitet 20.11.2025 21:57:49
kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality.
CVE-2025-63512
- EPSS 0.24%
- Veröffentlicht 18.11.2025 00:00:00
- Zuletzt bearbeitet 20.11.2025 21:58:59
kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleting doctor logic. The application fails to properly sanitize or parameterize user-supplied input from the demail parameter before i...
CVE-2023-41532
- EPSS 0.3%
- Veröffentlicht 07.08.2025 18:15:29
- Zuletzt bearbeitet 11.08.2025 14:45:38
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter in doctorsearch.php.