Kishan0725
Kishan0725 Hospital Management System: vulnerabilidades y CVE
Kishan0725 Hospital Management System tiene 20 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses9
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-69949 | Alta (7.3) | 0.21% | — | 29 jul 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email. |
| CVE-2025-69945 | Alta (7.3) | 0.20% | — | 29 jul 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1. |
| CVE-2025-69944 | Alta (7.3) | 0.20% | — | 29 jul 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter. |
| CVE-2025-69943 | Crítica (9.8) | 0.34% | — | 29 jul 2026 | kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid. |
| CVE-2025-69942 | Crítica (9.8) | 0.32% | — | 29 jul 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1. |
| CVE-2025-65340 | Crítica (9.8) | 0.32% | — | 29 jul 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php. |
| CVE-2025-63514 | Media (6.1) | 0.20% | — | 18 nov 2025 | kishan0725 Hospital Management System has a Cross-Site Scripting (XSS) vulnerability in appsearch.php via the email parameter. |
| CVE-2025-63513 | Media (6.5) | 0.27% | — | 18 nov 2025 | kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality. |
| CVE-2025-63512 | Media (6.5) | 0.24% | — | 18 nov 2025 | kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleting doctor logic. The application fails to properly sanitize or parameterize user-supplied input… |
| CVE-2023-41532 | Alta (8.8) | 0.30% | — | 7 ago 2025 | Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter in doctorsearch.php. |
| CVE-2023-41531 | Alta (8.8) | 0.30% | — | 7 ago 2025 | Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the username1 and password2 parameters. |
| CVE-2023-41530 | Crítica (9.8) | 0.35% | — | 7 ago 2025 | Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php. |
| CVE-2023-41529 | Media (6.1) | 0.20% | — | 7 ago 2025 | Hospital Management System v4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in func2.php via the fname and lname parameters. |
| CVE-2023-41528 | Crítica (9.8) | 0.35% | — | 7 ago 2025 | Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters. |
| CVE-2023-41527 | Crítica (9.8) | 0.35% | — | 7 ago 2025 | Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php. |
| CVE-2023-41526 | Crítica (9.8) | 0.35% | — | 7 ago 2025 | Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters. |
| CVE-2023-41525 | Crítica (9.8) | 0.35% | — | 7 ago 2025 | Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php. |
| CVE-2023-40992 | Media (6.5) | 0.22% | — | 7 ago 2025 | Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the password2 parameter. |
| CVE-2023-43958 | Crítica (9.8) | 1.2% | — | 22 abr 2025 | An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthenticated attacker to upload any file to the server and execute… |
| CVE-2024-45983 | Media (6.3) | 0.15% | — | 26 sept 2024 | A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The vulnerability allows an attacker to craft a malicious HTML form that submits a request to delete a… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.