Vulnerabilities > Phpgurukul > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-08-06 | CVE-2024-41333 | Cross-site Scripting vulnerability in PHPgurukul Tourism Management System 2.0 A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the uname parameter. | 6.1 |
2024-01-18 | CVE-2024-0652 | Cross-site Scripting vulnerability in PHPgurukul Company Visitor Management System 1.0 A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. | 4.8 |
2024-01-13 | CVE-2024-0476 | Cross-site Scripting vulnerability in PHPgurukul Blood Bank & Donor Management System 1.0 A vulnerability, which was classified as problematic, was found in Blood Bank & Donor Management 1.0. | 4.8 |
2024-01-12 | CVE-2023-51978 | SQL Injection vulnerability in PHPgurukul ART Gallery Management System 1.1 In PHPGurukul Art Gallery Management System v1.1, "Update Artist Image" functionality of "imageid" parameter is vulnerable to SQL Injection. | 6.5 |
2024-01-10 | CVE-2020-26627 | SQL Injection vulnerability in PHPgurukul Hospital Management System 4.0 A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under the 'Contact Us Queries -> Unread Query' tab. | 4.9 |
2024-01-10 | CVE-2020-26628 | Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 4.0 A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to execute arbitrary web scripts or HTML code via a malicious payload appended to a username on the 'Edit Profile" page and triggered by another user visiting the profile. | 6.1 |
2024-01-10 | CVE-2020-26630 | SQL Injection vulnerability in PHPgurukul Hospital Management System 4.0 A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an admin. | 4.9 |
2024-01-07 | CVE-2024-0286 | Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 1.0 A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. | 6.1 |
2023-12-30 | CVE-2023-7173 | Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 1.0 A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. | 5.4 |
2023-12-22 | CVE-2023-7055 | Incorrect Permission Assignment for Critical Resource vulnerability in PHPgurukul Online Notes Sharing System 1.0 A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0. | 5.4 |