First published: Tue Nov 05 2024(Updated: )
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulnerability affects unknown code of the file betweendates-detailsreports.php. The manipulation of the argument fromdate/todate leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Anujkumar Hospital Management System | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10806 is considered a problematic vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2024-10806, validate and sanitize the 'fromdate' and 'todate' parameters in betweendates-detailsreports.php to prevent cross-site scripting.
CVE-2024-10806 affects version 4.0 of the Anujkumar Hospital Management System.
CVE-2024-10806 can be exploited for cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
CVE-2024-10806 is found in the betweendates-detailsreports.php file of the PHPGurukul Hospital Management System.