Vulnerabilities > Phpgurukul > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-06 CVE-2024-41333 Cross-site Scripting vulnerability in PHPgurukul Tourism Management System 2.0
A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the uname parameter.
network
low complexity
phpgurukul CWE-79
6.1
2024-01-18 CVE-2024-0652 Cross-site Scripting vulnerability in PHPgurukul Company Visitor Management System 1.0
A vulnerability was found in PHPGurukul Company Visitor Management System 1.0.
network
low complexity
phpgurukul CWE-79
4.8
2024-01-13 CVE-2024-0476 Cross-site Scripting vulnerability in PHPgurukul Blood Bank & Donor Management System 1.0
A vulnerability, which was classified as problematic, was found in Blood Bank & Donor Management 1.0.
network
low complexity
phpgurukul CWE-79
4.8
2024-01-12 CVE-2023-51978 SQL Injection vulnerability in PHPgurukul ART Gallery Management System 1.1
In PHPGurukul Art Gallery Management System v1.1, "Update Artist Image" functionality of "imageid" parameter is vulnerable to SQL Injection.
network
low complexity
phpgurukul CWE-89
6.5
2024-01-10 CVE-2020-26627 SQL Injection vulnerability in PHPgurukul Hospital Management System 4.0
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under the 'Contact Us Queries -> Unread Query' tab.
network
low complexity
phpgurukul CWE-89
4.9
2024-01-10 CVE-2020-26628 Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 4.0
A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to execute arbitrary web scripts or HTML code via a malicious payload appended to a username on the 'Edit Profile" page and triggered by another user visiting the profile.
network
low complexity
phpgurukul CWE-79
6.1
2024-01-10 CVE-2020-26630 SQL Injection vulnerability in PHPgurukul Hospital Management System 4.0
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an admin.
network
low complexity
phpgurukul CWE-89
4.9
2024-01-07 CVE-2024-0286 Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 1.0
A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0.
network
low complexity
phpgurukul CWE-79
6.1
2023-12-30 CVE-2023-7173 Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 1.0
A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0.
network
low complexity
phpgurukul CWE-79
5.4
2023-12-22 CVE-2023-7055 Incorrect Permission Assignment for Critical Resource vulnerability in PHPgurukul Online Notes Sharing System 1.0
A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0.
network
low complexity
phpgurukul CWE-732
5.4