Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Hospital_management_system
(Hospital_management_system_project)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 43 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2022-02-28 | CVE-2022-25407 | Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doctor parameter at /admin-panel1.php. | Hospital_management_system | 5.4 | ||
2022-02-28 | CVE-2022-25408 | Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpassword parameter at /admin-panel1.php. | Hospital_management_system | 5.4 | ||
2022-02-28 | CVE-2022-25409 | Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php. | Hospital_management_system | 5.4 | ||
2022-03-15 | CVE-2022-25490 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php. | Hospital_management_system | 9.8 | ||
2022-03-15 | CVE-2022-25492 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php. | Hospital_management_system | 9.8 | ||
2022-03-15 | CVE-2022-25491 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php. | Hospital_management_system | 7.5 | ||
2022-03-15 | CVE-2022-25493 | HMS v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via treatmentrecord.php. | Hospital_management_system | 6.1 | ||
2022-03-31 | CVE-2022-24136 | Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php. To exploit, an attacker can upload any PHP file, and then execute it. | Hospital_management_system | 9.8 | ||
2022-03-31 | CVE-2022-26546 | Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive information and obtain the admin password. | Hospital_management_system | 9.1 | ||
2022-04-26 | CVE-2022-27299 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php. | Hospital_management_system | 9.8 |