CVE-2025-70064: High severity Phpgurukul Hospital Management System vulnerability
PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor Management) by manually browsing to the /admin/ directory after authentication. This allows any self-registered user to takeover the application, view confidential logs, and modify system data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70064?
CVE-2025-70064 has a low severity rating, but it exposes critical administrative functionalities to low-privileged users.
How do I fix CVE-2025-70064?
To fix CVE-2025-70064, restrict access to the /admin/ directory by implementing proper access controls.
What systems are affected by CVE-2025-70064?
CVE-2025-70064 affects PHPGurukul Hospital Management System version 4.0.
What is the impact of CVE-2025-70064?
The impact of CVE-2025-70064 allows low-privileged users to access the Administrator Dashboard and gain unauthorized privileges.
Who can exploit CVE-2025-70064?
Any authenticated low-privileged user, such as a patient, can exploit CVE-2025-70064 to access restricted administrative areas.