CVE-2023-41531
- EPSS 0.3%
- Veröffentlicht 07.08.2025 18:15:29
- Zuletzt bearbeitet 11.08.2025 14:45:29
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the username1 and password2 parameters.
CVE-2023-41530
- EPSS 0.35%
- Veröffentlicht 07.08.2025 18:15:29
- Zuletzt bearbeitet 11.08.2025 14:45:20
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.
CVE-2023-41529
- EPSS 0.2%
- Veröffentlicht 07.08.2025 00:00:00
- Zuletzt bearbeitet 11.08.2025 14:45:13
Hospital Management System v4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in func2.php via the fname and lname parameters.
CVE-2023-41528
- EPSS 0.35%
- Veröffentlicht 07.08.2025 00:00:00
- Zuletzt bearbeitet 11.08.2025 14:45:05
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters.
CVE-2023-41527
- EPSS 0.35%
- Veröffentlicht 07.08.2025 00:00:00
- Zuletzt bearbeitet 11.08.2025 14:44:57
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.
CVE-2023-41526
- EPSS 0.35%
- Veröffentlicht 07.08.2025 00:00:00
- Zuletzt bearbeitet 11.08.2025 14:44:48
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters.
CVE-2023-41525
- EPSS 0.35%
- Veröffentlicht 07.08.2025 00:00:00
- Zuletzt bearbeitet 11.08.2025 14:44:41
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.
CVE-2023-40992
- EPSS 0.22%
- Veröffentlicht 07.08.2025 00:00:00
- Zuletzt bearbeitet 11.08.2025 14:44:27
Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the password2 parameter.
CVE-2023-43958
- EPSS 1.14%
- Veröffentlicht 22.04.2025 00:00:00
- Zuletzt bearbeitet 14.05.2025 13:14:04
An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthenticated attacker to upload any file to the server and execute arbitrary code.
CVE-2024-45983
- EPSS 0.14%
- Veröffentlicht 26.09.2024 16:15:08
- Zuletzt bearbeitet 16.05.2025 20:29:29
A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The vulnerability allows an attacker to craft a malicious HTML form that submits a request to delete a doctor record. By enticing an au...