« Volver al listado

Phpgurukul

Phpgurukul Hospital Management System: vulnerabilidades y CVE

Phpgurukul Hospital Management System tiene 62 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 11 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE62
Últimos 12 meses6
Críticas11
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-70064Alta (8.8)0.48%—18 feb 2026
PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor…
CVE-2025-70063Media (6.5)0.34%—18 feb 2026
The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vulnerability. The application fails to verify that the requested 'viewid' parameter belongs…
CVE-2025-70062Media (6.5)0.18%—18 feb 2026
PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fails to enforce CSRF token validation on the add-doctor.php endpoint.…
CVE-2026-2179Baja (2)0.36%—8 feb 2026
A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. This manipulation of the argument ID causes sql injection. The attack…
CVE-2026-2134Baja (2)0.36%—8 feb 2026
A security vulnerability has been detected in PHPGurukul Hospital Management System 4.0. The affected element is an unknown function of the file /hms/admin/manage-doctors.php. Such manipulation of the argument ID leads…
CVE-2026-1550Baja (2.1)0.40%—28 ene 2026
A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/adminviews.py of the component Admin…
CVE-2025-56216Alta (8.5)0.29%—25 ago 2025
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in about-us.php via the pagetitle parameter.
CVE-2025-56215Media (6.5)0.27%—25 ago 2025
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in contact.php via the pagetitle parameter.
CVE-2025-56214Crítica (9.8)0.35%—25 ago 2025
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter.
CVE-2025-56212Crítica (9.8)0.43%—25 ago 2025
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in add-doctor.php via the docname parameter.
CVE-2025-7604Media (5.5)0.44%—14 jul 2025
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /user-login.php. The manipulation of the…
CVE-2025-7176Media (5.5)0.64%—8 jul 2025
A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file view-medhistory.php. The manipulation of…
CVE-2024-51360Crítica (9.8)0.92%—23 may 2025
An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor/edit-profile.php file
CVE-2024-56990Media (4.5)0.40%—21 ene 2025
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /view-medhistory.php and /admin/view-patient.php.
CVE-2024-56998Media (4.2)0.20%—21 ene 2025
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /edit-profile.php via the parameter $address.
CVE-2024-56997Media (4.2)0.20%—21 ene 2025
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /doctor/index.php via the 'Email' parameter.
CVE-2024-11675Media (5.3)0.48%—26 nov 2024
A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file…
CVE-2024-46239Media (5.9)0.30%—21 oct 2024
Multiple cross-site scripting vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /doctor/edit-profile.php and adminremark parameter in /admin/query-details.php.
CVE-2024-46238Media (5.9)0.30%—21 oct 2024
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php
CVE-2024-46237Media (5.4)0.32%—9 oct 2024
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.
CVE-2022-46499Alta (8.8)0.55%—7 mar 2024
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php.
CVE-2022-46498Baja (2.7)0.44%—7 mar 2024
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php.
CVE-2022-46497Alta (8.1)0.50%—7 mar 2024
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_view_single_patien.php.
CVE-2020-26630Media (4.9)0.71%—10 ene 2024
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the…
CVE-2020-26629Crítica (9.8)1.2%—10 ene 2024
A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the server.
CVE-2020-26628Media (6.1)0.50%—10 ene 2024
A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to execute arbitrary web scripts or HTML code via a malicious payload appended to a username on the…
CVE-2020-26627Media (4.9)0.71%—10 ene 2024
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under…
CVE-2024-0364Crítica (9.8)0.53%—10 ene 2024
A vulnerability, which was classified as critical, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file admin/query-details.php. The manipulation of the argument adminremark…
CVE-2024-0363Crítica (9.8)0.65%—10 ene 2024
A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file admin/patient-search.php. The manipulation…
CVE-2024-0362Crítica (9.8)0.65%—10 ene 2024
A vulnerability classified as critical was found in PHPGurukul Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/change-password.php. The manipulation of the…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System3
  2. T1190 Exploit Public-Facing Application3
  3. T1210 Exploitation of Remote Services2
  4. T1059 Command and Scripting Interpreter1
  5. T1078.001 Default Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Phpgurukul