VYPR

Edoc-doctor-appointment-system

by HashenUdara

CVEs (7)

  • CVE-2022-36545CriAug 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php.

  • CVE-2022-36544CriAug 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php.

  • CVE-2022-36543CriAug 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php.

  • CVE-2022-36546HigAug 26, 2022
    risk 0.57cvss 8.8epss 0.00

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/settings.php.

  • CVE-2022-36542MedAug 26, 2022
    risk 0.42cvss 6.5epss 0.01

    An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitrarily edit, read, and delete Administrator data.

  • CVE-2022-36547MedAug 26, 2022
    risk 0.40cvss 6.1epss 0.01

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /patient/index.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search field.

  • CVE-2022-36548MedAug 26, 2022
    risk 0.35cvss 5.4epss 0.01

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability at /patient/settings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field.