CVE-2025-45805: XSS
In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-45805?
CVE-2025-45805 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-45805?
To fix CVE-2025-45805, ensure proper input sanitization and validation for user profile fields in the Doctor Appointment Management System.
Who is affected by CVE-2025-45805?
Authenticated doctor users of the phpgurukul Doctor Appointment Management System 1.0 are affected by CVE-2025-45805.
What type of attack does CVE-2025-45805 enable?
CVE-2025-45805 enables cross-site scripting (XSS) attacks through arbitrary JavaScript injection.
What is the impact of CVE-2025-45805 on users?
The impact of CVE-2025-45805 on users is that it can lead to unauthorized actions or data exposure when they interact with compromised doctor profiles.