First published: Fri Oct 21 2022(Updated: )
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via doctor/view-patient.php, admin/view-patient.php, and view-medhistory.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hospital Management System Project Hospital Management System | =4.0 | |
PHPGURUKUL Hospital Management System | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-42206.
This vulnerability is a Cross Site Scripting (XSS) vulnerability.
The PHPGurukul Hospital Management System version 4.0 is affected by this vulnerability.
The vulnerability can be exploited by injecting malicious scripts into the doctor/view-patient.php, admin/view-patient.php, and view-medhistory.php pages.
The severity of this vulnerability is medium, with a CVSS score of 5.4.
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-79.
It is recommended to update the PHPGurukul Hospital Management System to a version that has resolved this vulnerability.