Product:

Edoc\-Doctor\-Appointment\-System

(Edoc\-Doctor\-Appointment\-System_project)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 7
Date Id Summary Products Score Patch Annotated
2022-08-26 CVE-2022-36542 An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitrarily edit, read, and delete Administrator data. Edoc\-Doctor\-Appointment\-System 6.5
2022-08-26 CVE-2022-36543 Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php. Edoc\-Doctor\-Appointment\-System 9.8
2022-08-26 CVE-2022-36544 Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php. Edoc\-Doctor\-Appointment\-System 9.8
2022-08-26 CVE-2022-36545 Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php. Edoc\-Doctor\-Appointment\-System 9.8
2022-08-26 CVE-2022-36547 Edoc-doctor-appointment-system v1.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /patient/index.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search field. Edoc\-Doctor\-Appointment\-System 6.1
2022-08-26 CVE-2022-36546 Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/settings.php. Edoc\-Doctor\-Appointment\-System 8.8
2022-08-26 CVE-2022-36548 Edoc-doctor-appointment-system v1.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability at /patient/settings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field. Edoc\-Doctor\-Appointment\-System 5.4