CVE-2024-10806: PHPGurukul Hospital Management System betweendates-detailsreports.php cross site scripting
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulnerability affects unknown code of the file betweendates-detailsreports.php. The manipulation of the argument fromdate/todate leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10806?
CVE-2024-10806 is considered a problematic vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2024-10806?
To fix CVE-2024-10806, validate and sanitize the 'fromdate' and 'todate' parameters in betweendates-detailsreports.php to prevent cross-site scripting.
Which software versions are affected by CVE-2024-10806?
CVE-2024-10806 affects version 4.0 of the Anujkumar Hospital Management System.
What types of attacks can CVE-2024-10806 be used for?
CVE-2024-10806 can be exploited for cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
Where in the code is CVE-2024-10806 found?
CVE-2024-10806 is found in the betweendates-detailsreports.php file of the PHPGurukul Hospital Management System.