Vulnerabilities > Hospital Management System Project

DATE CVE VULNERABILITY TITLE RISK
2023-06-28 CVE-2023-34651 Cross-site Scripting vulnerability in Hospital Management System Project Hospital Management System 1.0
PHPgurukl Hospital Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).
6.1
2023-01-20 CVE-2022-48120 SQL Injection vulnerability in Hospital Management System Project Hospital Management System 1.0/20210313/4.0
SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on March 13, 2021), allows attackers to execute arbitrary commands via the contact and doctor parameters to /search.php.
network
low complexity
hospital-management-system-project CWE-89
critical
9.8
2023-01-13 CVE-2022-46093 SQL Injection vulnerability in Hospital Management System Project Hospital Management System 1.0
Hospital Management System v1.0 is vulnerable to SQL Injection.
8.2
2022-09-13 CVE-2022-38637 SQL Injection vulnerability in Hospital Management System Project Hospital Management System 1.0
Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page.
network
low complexity
hospital-management-system-project CWE-89
critical
9.8
2022-07-20 CVE-2022-34590 SQL Injection vulnerability in Hospital Management System Project Hospital Management System 1.0
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php.
7.2
2022-07-01 CVE-2022-32093 SQL Injection vulnerability in Hospital Management System Project Hospital Management System 1.0
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at adminlogin.php.
network
low complexity
hospital-management-system-project CWE-89
critical
9.8
2022-07-01 CVE-2022-32094 SQL Injection vulnerability in Hospital Management System Project Hospital Management System 1.0
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.php.
network
low complexity
hospital-management-system-project CWE-89
critical
9.8
2022-07-01 CVE-2022-32095 SQL Injection vulnerability in Hospital Management System Project Hospital Management System 1.0
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at orders.php.
network
low complexity
hospital-management-system-project CWE-89
critical
9.8
2022-06-02 CVE-2021-44095 SQL Injection vulnerability in Hospital Management System Project Hospital Management System 1.0
A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote attacker to compromise Application SQL database.
network
low complexity
hospital-management-system-project CWE-89
critical
9.8
2022-05-26 CVE-2022-30516 SQL Injection vulnerability in Hospital Management System Project Hospital Management System 1.0
In Hospital-Management-System v1.0, the editid parameter in the doctor.php page is vulnerable to SQL injection attacks.
network
low complexity
hospital-management-system-project CWE-89
critical
9.8