First published: Thu Oct 08 2020(Updated: )
PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHPGurukul Hospital Management System in PHP | =4.0 | |
PHPGURUKUL Hospital Management System | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-25271 is medium with a CVSS score of 5.4.
CVE-2020-25271 allows XSS attacks through specific pages such as admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.
To fix CVE-2020-25271, you should update to a fixed version or apply the recommended patch provided by PHPGurukul.
You can find more information about CVE-2020-25271 on the GitHub page: https://github.com/Ko-kn3t/CVE-2020-25271 and the PHPGurukul website: https://phpgurukul.com.