Vulnerabilities > Phpgurukul > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-06-22 CVE-2020-22167 Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 4.0
PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php.
network
low complexity
phpgurukul CWE-79
5.4
2021-05-26 CVE-2021-33469 Cross-site Scripting vulnerability in PHPgurukul Covid19 Testing Management System 1.0
COVID19 Testing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the "Admin name" parameter.
network
low complexity
phpgurukul CWE-79
4.8
2021-04-15 CVE-2021-27545 SQL Injection vulnerability in PHPgurukul Beauty Parlour Management System 1.0
SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to obtain sensitive database information by injecting SQL commands into the "sername" parameter.
network
low complexity
phpgurukul CWE-89
6.5
2021-04-15 CVE-2021-27544 Cross-site Scripting vulnerability in PHPgurukul Beauty Parlour Management System 1.0
Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "sername" parameter.
network
low complexity
phpgurukul CWE-79
4.8
2021-02-08 CVE-2020-26052 Cross-site Scripting vulnerability in PHPgurukul Online Marriage Registration System 1.0
Online Marriage Registration System 1.0 is affected by stored cross-site scripting (XSS) vulnerabilities in multiple parameters.
network
low complexity
phpgurukul CWE-79
5.4
2021-01-29 CVE-2021-26303 Cross-site Scripting vulnerability in PHPgurukul Daily Expense Tracker System 1.0
PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field.
network
phpgurukul CWE-79
4.3
2020-10-08 CVE-2020-25271 Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 4.0
PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.
network
low complexity
phpgurukul CWE-79
5.4
2020-10-08 CVE-2020-25270 Cross-site Scripting vulnerability in PHPgurukul Hostel Management System 2.1
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City.
network
low complexity
phpgurukul CWE-79
5.4
2020-01-14 CVE-2020-5193 Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 4.0
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or Doctorspecialization parameter.
network
low complexity
phpgurukul CWE-79
6.1
2020-01-09 CVE-2020-5308 Cross-site Scripting vulnerability in PHPgurukul Dairy Farm Shop Management System 1.0
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to XSS, as demonstrated by the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName parameter in add-product.php.
network
low complexity
phpgurukul CWE-79
6.1