CVE-2020-35745: High severity phpgurukul hospital management system vulnerability
PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-35745?
The severity of CVE-2020-35745 is high.
How does CVE-2020-35745 affect PHPGURUKUL Hospital Management System V 4.0?
CVE-2020-35745 allows attackers to access all data of users, doctors, patients, change admin password, get appointment history, and access all session logs in PHPGURUKUL Hospital Management System V 4.0.
How can an attacker exploit CVE-2020-35745?
An attacker can exploit CVE-2020-35745 by accessing admin/dashboard.php in PHPGURUKUL Hospital Management System V 4.0, which allows them to bypass access restrictions and gain unauthorized access to sensitive data.
Is there a fix available for CVE-2020-35745?
Currently, there is no available fix for CVE-2020-35745. It is recommended to follow the vendor's security advisories for any updates or patches.
Where can I find more information about CVE-2020-35745?
More information about CVE-2020-35745 can be found in the provided references: [Link 1](https://medium.com/@ashketchum/privilege-escalation-unauthenticated-access-to-admin-portal-cve-2020-35745-bb5d5dca97a0), [Link 2](https://www.phpgurukul.com/hospital-management-system-in-php/), [Link 3](https://www.youtube.com/watch?v=vnSsg6iwV9Y&feature=youtu.be&ab_channel=ashketchum).