VYPR

Hospital Management System

by Kashipara

CVEs (12)

  • CVE-2024-42773CriAug 22, 2024
    risk 0.59cvss 9.1epss 0.00

    An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel room entries in the administrator section.

  • CVE-2024-42775CriAug 22, 2024
    risk 0.59cvss 9.1epss 0.00

    An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via the direct URL access.

  • CVE-2024-42774HigAug 22, 2024
    risk 0.49cvss 7.5epss 0.00

    An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room entries in the administrator section.

  • CVE-2024-42772HigAug 22, 2024
    risk 0.49cvss 7.5epss 0.00

    An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room entries in administrator section.

  • CVE-2024-0268HigJan 7, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Kashipara Hospital Management System up to 1.0. Affected by this issue is some unknown functionality of the file registration.php. The manipulation of the argument name/email/pass/gender/age/city leads to sql…

  • CVE-2024-0267HigJan 7, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in Kashipara Hospital Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file login.php of the component Parameter Handler. The manipulation of the argument email/password leads to sql…

  • CVE-2024-42767HigAug 22, 2024
    risk 0.47cvss 7.2epss 0.01

    Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.

  • CVE-2024-42776HigAug 22, 2024
    risk 0.47cvss 7.2epss 0.01

    Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.

  • CVE-2024-42768MedAug 22, 2024
    risk 0.44cvss 6.8epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php.

  • CVE-2024-42769MedAug 22, 2024
    risk 0.40cvss 6.1epss 0.00

    A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "user_fname" and "user_lname" parameters.

  • CVE-2024-42771MedAug 22, 2024
    risk 0.31cvss 4.8epss 0.00

    A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "room_name" parameter.

  • CVE-2024-42770MedAug 22, 2024
    risk 0.31cvss 4.7epss 0.00

    A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via the "user_email" parameter.