Hospital Management System
by Phpgurukul
CVEs (75)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24263 | Cri | 0.67 | 9.8 | 0.08 | Jan 31, 2022 | Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter. | ||
| CVE-2025-56214 | Cri | 0.64 | 9.8 | 0.00 | Aug 25, 2025 | phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter. | ||
| CVE-2025-56212 | Cri | 0.64 | 9.8 | 0.00 | Aug 25, 2025 | phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in add-doctor.php via the docname parameter. | ||
| CVE-2023-41527 | Cri | 0.64 | 9.8 | 0.00 | Aug 7, 2025 | Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php. | ||
| CVE-2024-51360 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2025 | An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor/edit-profile.php file | ||
| CVE-2020-26629 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the server. | ||
| CVE-2023-31498 | Cri | 0.64 | 9.8 | 0.02 | May 11, 2023 | A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code and access sensitive information via the session token parameter. | ||
| CVE-2022-30449 | Cri | 0.64 | 9.8 | 0.02 | May 11, 2022 | Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php. | ||
| CVE-2022-30448 | Cri | 0.64 | 9.8 | 0.02 | May 11, 2022 | Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php. | ||
| CVE-2020-5192 | Hig | 0.62 | 8.8 | 0.17 | Jan 6, 2020 | PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised. | ||
| CVE-2025-70064 | Hig | 0.57 | 8.8 | 0.00 | Feb 18, 2026 | PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor Management) by manually browsing to the /admin/ directory after… | ||
| CVE-2022-46499 | Hig | 0.57 | 8.8 | 0.01 | Mar 7, 2024 | Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php. | ||
| CVE-2021-35387 | Hig | 0.57 | 8.8 | 0.01 | Oct 28, 2022 | Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php. | ||
| CVE-2020-35745 | Hig | 0.57 | 8.8 | 0.02 | Jan 7, 2021 | PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs. | ||
| CVE-2025-56216 | Hig | 0.55 | 8.5 | 0.00 | Aug 25, 2025 | phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in about-us.php via the pagetitle parameter. | ||
| CVE-2022-46497 | Hig | 0.53 | 8.1 | 0.01 | Mar 7, 2024 | Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_view_single_patien.php. | ||
| CVE-2022-24226 | Hig | 0.49 | 7.5 | 0.02 | Feb 15, 2022 | Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.php. | ||
| CVE-2022-24646 | Hig | 0.49 | 7.5 | 0.02 | Feb 10, 2022 | Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters. | ||
| CVE-2020-22176 | Hig | 0.49 | 7.5 | 0.02 | Jun 22, 2021 | PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information. | ||
| CVE-2020-22175 | Hig | 0.49 | 7.5 | 0.02 | Jun 22, 2021 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. |
- risk 0.67cvss 9.8epss 0.08
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.
- risk 0.64cvss 9.8epss 0.00
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter.
- risk 0.64cvss 9.8epss 0.00
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in add-doctor.php via the docname parameter.
- risk 0.64cvss 9.8epss 0.00
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.
- risk 0.64cvss 9.8epss 0.01
An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor/edit-profile.php file
- risk 0.64cvss 9.8epss 0.01
A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the server.
- risk 0.64cvss 9.8epss 0.02
A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code and access sensitive information via the session token parameter.
- risk 0.64cvss 9.8epss 0.02
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php.
- risk 0.64cvss 9.8epss 0.02
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php.
- risk 0.62cvss 8.8epss 0.17
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.
- risk 0.57cvss 8.8epss 0.00
PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor Management) by manually browsing to the /admin/ directory after…
- risk 0.57cvss 8.8epss 0.01
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php.
- risk 0.57cvss 8.8epss 0.01
Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.
- risk 0.57cvss 8.8epss 0.02
PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.
- risk 0.55cvss 8.5epss 0.00
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in about-us.php via the pagetitle parameter.
- risk 0.53cvss 8.1epss 0.01
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_view_single_patien.php.
- risk 0.49cvss 7.5epss 0.02
Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.php.
- risk 0.49cvss 7.5epss 0.02
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.
- risk 0.49cvss 7.5epss 0.02
PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information.
- risk 0.49cvss 7.5epss 0.02
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Page 1 of 4