Medium severity6.5NVD Advisory· Published Feb 18, 2026· Updated Jun 17, 2026
CVE-2025-70062
CVE-2025-70062
Description
PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fails to enforce CSRF token validation on the add-doctor.php endpoint. This allows remote attackers to create arbitrary Doctor accounts (privileged users) by tricking an authenticated administrator into visiting a malicious page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3= 4.0+ 2 more
- (no CPE)range: = 4.0
- cpe:2.3:a:phpgurukul:hospital_management_system:4.0:*:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
2- gist.github.com/Sanka1pp/78795abd84220e879ee0425159af5ae2nvdExploit
- packetstorm.news/files/id/213711nvdExploitMitigationThird Party Advisory
News mentions
0No linked articles in our index yet.