First published: Thu Jan 07 2021(Updated: )
PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHPGurukul Hospital Management System in PHP | =4.0 | |
PHPGURUKUL Hospital Management System | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-35745 is high.
CVE-2020-35745 allows attackers to access all data of users, doctors, patients, change admin password, get appointment history, and access all session logs in PHPGURUKUL Hospital Management System V 4.0.
An attacker can exploit CVE-2020-35745 by accessing admin/dashboard.php in PHPGURUKUL Hospital Management System V 4.0, which allows them to bypass access restrictions and gain unauthorized access to sensitive data.
Currently, there is no available fix for CVE-2020-35745. It is recommended to follow the vendor's security advisories for any updates or patches.
More information about CVE-2020-35745 can be found in the provided references: [Link 1](https://medium.com/@ashketchum/privilege-escalation-unauthenticated-access-to-admin-portal-cve-2020-35745-bb5d5dca97a0), [Link 2](https://www.phpgurukul.com/hospital-management-system-in-php/), [Link 3](https://www.youtube.com/watch?v=vnSsg6iwV9Y&feature=youtu.be&ab_channel=ashketchum).