Hospital Management System
Source repositories
CVEs (64)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-34590 | Hig | 0.47 | 7.2 | 0.04 | Jul 20, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php. | ||
| CVE-2022-29318 | Hig | 0.47 | 7.2 | 0.01 | May 11, 2022 | An arbitrary file upload vulnerability in the New Entry module of Car Rental Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2023-40992 | Med | 0.42 | 6.5 | 0.00 | Aug 7, 2025 | Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the password2 parameter. | ||
| CVE-2023-3811 | Med | 0.41 | 6.3 | 0.01 | Jul 21, 2023 | A vulnerability was found in Hospital Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file patientprofile.php. The manipulation of the argument address leads to sql injection. The attack may be initiated remotely. The… | ||
| CVE-2023-3810 | Med | 0.41 | 6.3 | 0.01 | Jul 21, 2023 | A vulnerability was found in Hospital Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file patientappointment.php. The manipulation of the argument loginid/password/mobileno/appointmentdate/appointmenttime/patiente/dob/doct/… | ||
| CVE-2023-3809 | Med | 0.41 | 6.3 | 0.01 | Jul 21, 2023 | A vulnerability was found in Hospital Management System 1.0. It has been classified as critical. This affects an unknown part of the file patient.php. The manipulation of the argument address leads to sql injection. It is possible to initiate the attack remotely. The exploit has… | ||
| CVE-2023-3808 | Med | 0.41 | 6.3 | 0.01 | Jul 21, 2023 | A vulnerability was found in Hospital Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file patientforgotpassword.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been… | ||
| CVE-2022-4012 | Med | 0.41 | 6.3 | 0.00 | Nov 16, 2022 | A vulnerability classified as critical has been found in Hospital Management Center. Affected is an unknown function of the file patient-info.php. The manipulation of the argument pt_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | ||
| CVE-2023-41529 | Med | 0.40 | 6.1 | 0.00 | Aug 7, 2025 | Hospital Management System v4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in func2.php via the fname and lname parameters. | ||
| CVE-2025-29410 | Med | 0.40 | 6.1 | 0.00 | Mar 20, 2025 | A cross-site scripting (XSS) vulnerability in the component /contact.php of Hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the txtEmail parameter. | ||
| CVE-2020-26628 | Med | 0.40 | 6.1 | 0.01 | Jan 10, 2024 | A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to execute arbitrary web scripts or HTML code via a malicious payload appended to a username on the 'Edit Profile" page and triggered by another user visiting… | ||
| CVE-2023-36939 | Med | 0.40 | 6.1 | 0.01 | Jul 10, 2023 | Cross-Site Scripting (XSS) vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the search booking field. | ||
| CVE-2021-38757 | Med | 0.40 | 6.1 | 0.01 | Aug 16, 2021 | Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php. | ||
| CVE-2023-36375 | Med | 0.35 | 5.4 | 0.01 | Jul 10, 2023 | Cross Site Scripting vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the Guardian name, Guardian relation, complimentary address, city, permanent address, and city parameters in the Book Hostel & Room Details… | ||
| CVE-2021-35388 | Med | 0.35 | 5.4 | 0.00 | Oct 28, 2022 | Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php. | ||
| CVE-2022-25409 | Med | 0.35 | 5.4 | 0.00 | Feb 28, 2022 | Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php. | ||
| CVE-2022-25408 | Med | 0.35 | 5.4 | 0.00 | Feb 28, 2022 | Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpassword parameter at /admin-panel1.php. | ||
| CVE-2022-25407 | Med | 0.35 | 5.4 | 0.00 | Feb 28, 2022 | Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doctor parameter at /admin-panel1.php. | ||
| CVE-2021-38755 | Med | 0.35 | 5.3 | 0.01 | Aug 16, 2021 | Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php. | ||
| CVE-2020-26630 | Med | 0.32 | 4.9 | 0.01 | Jan 10, 2024 | A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an admin. |
- risk 0.47cvss 7.2epss 0.04
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php.
- risk 0.47cvss 7.2epss 0.01
An arbitrary file upload vulnerability in the New Entry module of Car Rental Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.42cvss 6.5epss 0.00
Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the password2 parameter.
- risk 0.41cvss 6.3epss 0.01
A vulnerability was found in Hospital Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file patientprofile.php. The manipulation of the argument address leads to sql injection. The attack may be initiated remotely. The…
- risk 0.41cvss 6.3epss 0.01
A vulnerability was found in Hospital Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file patientappointment.php. The manipulation of the argument loginid/password/mobileno/appointmentdate/appointmenttime/patiente/dob/doct/…
- risk 0.41cvss 6.3epss 0.01
A vulnerability was found in Hospital Management System 1.0. It has been classified as critical. This affects an unknown part of the file patient.php. The manipulation of the argument address leads to sql injection. It is possible to initiate the attack remotely. The exploit has…
- risk 0.41cvss 6.3epss 0.01
A vulnerability was found in Hospital Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file patientforgotpassword.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been…
- risk 0.41cvss 6.3epss 0.00
A vulnerability classified as critical has been found in Hospital Management Center. Affected is an unknown function of the file patient-info.php. The manipulation of the argument pt_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
- risk 0.40cvss 6.1epss 0.00
Hospital Management System v4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in func2.php via the fname and lname parameters.
- risk 0.40cvss 6.1epss 0.00
A cross-site scripting (XSS) vulnerability in the component /contact.php of Hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the txtEmail parameter.
- risk 0.40cvss 6.1epss 0.01
A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to execute arbitrary web scripts or HTML code via a malicious payload appended to a username on the 'Edit Profile" page and triggered by another user visiting…
- risk 0.40cvss 6.1epss 0.01
Cross-Site Scripting (XSS) vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the search booking field.
- risk 0.40cvss 6.1epss 0.01
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.
- risk 0.35cvss 5.4epss 0.01
Cross Site Scripting vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the Guardian name, Guardian relation, complimentary address, city, permanent address, and city parameters in the Book Hostel & Room Details…
- risk 0.35cvss 5.4epss 0.00
Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php.
- risk 0.35cvss 5.4epss 0.00
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.
- risk 0.35cvss 5.4epss 0.00
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpassword parameter at /admin-panel1.php.
- risk 0.35cvss 5.4epss 0.00
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doctor parameter at /admin-panel1.php.
- risk 0.35cvss 5.3epss 0.01
Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php.
- risk 0.32cvss 4.9epss 0.01
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an admin.
Page 3 of 4