High severity8.8NVD Advisory· Published Jan 7, 2021· Updated Jun 17, 2026
CVE-2020-35745
CVE-2020-35745
Description
PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:phpgurukul:hospital_management_system:4.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:phpgurukul:hospital_management_system:4.0:*:*:*:*:*:*:*
- (no CPE)range: = 4.0
- PHPGURUKUL/Hospital Management Systemdescription
Patches
Vulnerability mechanics
References
3- medium.com/%40ashketchum/privilege-escalation-unauthenticated-access-to-admin-portal-cve-2020-35745-bb5d5dca97a0nvdExploitThird Party Advisory
- www.youtube.com/watchnvdExploitThird Party Advisory
- www.phpgurukul.com/hospital-management-system-in-php/nvdProductThird Party Advisory
News mentions
0No linked articles in our index yet.