Vulnerabilities > Phpgurukul > Hospital Management System

DATE CVE VULNERABILITY TITLE RISK
2021-06-22 CVE-2020-22173 SQL Injection vulnerability in PHPgurukul Hospital Management System 4.0
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php.
network
low complexity
phpgurukul CWE-89
7.5
2021-06-22 CVE-2020-22174 SQL Injection vulnerability in PHPgurukul Hospital Management System 4.0
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php.
network
low complexity
phpgurukul CWE-89
7.5
2021-06-22 CVE-2020-22175 SQL Injection vulnerability in PHPgurukul Hospital Management System 4.0
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php.
network
low complexity
phpgurukul CWE-89
7.5
2021-06-22 CVE-2020-22176 Missing Authorization vulnerability in PHPgurukul Hospital Management System 4.0
PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas.
network
low complexity
phpgurukul CWE-862
7.5
2021-01-07 CVE-2020-35745 Missing Authorization vulnerability in PHPgurukul Hospital Management System 4.0
PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.
network
low complexity
phpgurukul CWE-862
8.8
2020-10-08 CVE-2020-25271 Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 4.0
PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.
network
low complexity
phpgurukul CWE-79
5.4
2020-01-14 CVE-2020-5193 Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 4.0
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or Doctorspecialization parameter.
network
low complexity
phpgurukul CWE-79
6.1
2020-01-06 CVE-2020-5192 SQL Injection vulnerability in PHPgurukul Hospital Management System 4.0
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.
network
low complexity
phpgurukul CWE-89
8.8
2020-01-06 CVE-2020-5191 Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 4.0
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.
network
low complexity
phpgurukul CWE-79
6.1