Vulnerabilities > Phpgurukul > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-06-22 | CVE-2020-22167 | Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 4.0 PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php. | 5.4 |
2021-05-26 | CVE-2021-33469 | Cross-site Scripting vulnerability in PHPgurukul Covid19 Testing Management System 1.0 COVID19 Testing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the "Admin name" parameter. | 4.8 |
2021-04-15 | CVE-2021-27545 | SQL Injection vulnerability in PHPgurukul Beauty Parlour Management System 1.0 SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to obtain sensitive database information by injecting SQL commands into the "sername" parameter. | 6.5 |
2021-04-15 | CVE-2021-27544 | Cross-site Scripting vulnerability in PHPgurukul Beauty Parlour Management System 1.0 Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "sername" parameter. | 4.8 |
2021-02-08 | CVE-2020-26052 | Cross-site Scripting vulnerability in PHPgurukul Online Marriage Registration System 1.0 Online Marriage Registration System 1.0 is affected by stored cross-site scripting (XSS) vulnerabilities in multiple parameters. | 5.4 |
2021-01-29 | CVE-2021-26303 | Cross-site Scripting vulnerability in PHPgurukul Daily Expense Tracker System 1.0 PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field. | 4.3 |
2020-10-08 | CVE-2020-25271 | Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 4.0 PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php. | 5.4 |
2020-10-08 | CVE-2020-25270 | Cross-site Scripting vulnerability in PHPgurukul Hostel Management System 2.1 PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City. | 5.4 |
2020-01-14 | CVE-2020-5193 | Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 4.0 PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or Doctorspecialization parameter. | 6.1 |
2020-01-09 | CVE-2020-5308 | Cross-site Scripting vulnerability in PHPgurukul Dairy Farm Shop Management System 1.0 PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to XSS, as demonstrated by the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName parameter in add-product.php. | 6.1 |