CVE-2024-46237: XSS
Published Oct 9, 2024
·Updated
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.
Affected Software
1 affected component
Phpgurukul Hospital Management System=4.0
Event History
Oct 9, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-46237?
CVE-2024-46237 is classified as a medium severity vulnerability due to its potential for exploitation via Cross Site Scripting.
2
How do I fix CVE-2024-46237?
To fix CVE-2024-46237, sanitize and validate the input for the patname, pataddress, and medhis parameters in the affected PHP files.
3
What systems are affected by CVE-2024-46237?
CVE-2024-46237 affects version 4.0 of the PHPGurukul Hospital Management System.
4
What type of vulnerability is CVE-2024-46237?
CVE-2024-46237 is a Cross Site Scripting (XSS) vulnerability.
5
What parameters are involved in CVE-2024-46237?
CVE-2024-46237 is triggered by the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.