CVE-2020-25271: XSS
Published Oct 8, 2020
·Updated
PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.
Affected Software
2 affected components
Phpgurukul Hospital Management System in PHP=4.0
Phpgurukul Hospital Management System=4.0
Event History
Oct 8, 2020
CVE Published
via MITRE·12:32 PM
Data Sourced
via MITRE·12:32 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-25271?
The severity of CVE-2020-25271 is medium with a CVSS score of 5.4.
2
How does CVE-2020-25271 allow XSS attacks?
CVE-2020-25271 allows XSS attacks through specific pages such as admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.
3
How can I fix CVE-2020-25271?
To fix CVE-2020-25271, you should update to a fixed version or apply the recommended patch provided by PHPGurukul.
4
Where can I find more information about CVE-2020-25271?
You can find more information about CVE-2020-25271 on the GitHub page: https://github.com/Ko-kn3t/CVE-2020-25271 and the PHPGurukul website: https://phpgurukul.com.