« Volver al listado

Kishan0725

Kishan0725 Hospital Management System: vulnerabilidades y CVE

Kishan0725 Hospital Management System tiene 20 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE20
Últimos 12 meses9
Críticas9
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-69949Alta (7.3)0.21%—29 jul 2026
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email.
CVE-2025-69945Alta (7.3)0.20%—29 jul 2026
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.
CVE-2025-69944Alta (7.3)0.20%—29 jul 2026
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter.
CVE-2025-69943Crítica (9.8)0.34%—29 jul 2026
kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.
CVE-2025-69942Crítica (9.8)0.32%—29 jul 2026
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.
CVE-2025-65340Crítica (9.8)0.32%—29 jul 2026
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.
CVE-2025-63514Media (6.1)0.20%—18 nov 2025
kishan0725 Hospital Management System has a Cross-Site Scripting (XSS) vulnerability in appsearch.php via the email parameter.
CVE-2025-63513Media (6.5)0.27%—18 nov 2025
kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality.
CVE-2025-63512Media (6.5)0.24%—18 nov 2025
kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleting doctor logic. The application fails to properly sanitize or parameterize user-supplied input…
CVE-2023-41532Alta (8.8)0.30%—7 ago 2025
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter in doctorsearch.php.
CVE-2023-41531Alta (8.8)0.30%—7 ago 2025
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the username1 and password2 parameters.
CVE-2023-41530Crítica (9.8)0.35%—7 ago 2025
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.
CVE-2023-41529Media (6.1)0.20%—7 ago 2025
Hospital Management System v4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in func2.php via the fname and lname parameters.
CVE-2023-41528Crítica (9.8)0.35%—7 ago 2025
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters.
CVE-2023-41527Crítica (9.8)0.35%—7 ago 2025
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.
CVE-2023-41526Crítica (9.8)0.35%—7 ago 2025
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters.
CVE-2023-41525Crítica (9.8)0.35%—7 ago 2025
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.
CVE-2023-40992Media (6.5)0.22%—7 ago 2025
Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the password2 parameter.
CVE-2023-43958Crítica (9.8)1.2%—22 abr 2025
An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthenticated attacker to upload any file to the server and execute…
CVE-2024-45983Media (6.3)0.15%—26 sept 2024
A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The vulnerability allows an attacker to craft a malicious HTML form that submits a request to delete a…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System13
  2. T1190 Exploit Public-Facing Application12
  3. T1203 Exploitation for Client Execution2
  4. T1059 Command and Scripting Interpreter1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Kishan0725