Vendor CVEs
Hospital\'s Patient Records Management System Project
All CVEs
26 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-32337 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/patients/manage_patient.php?id=. | ||
| CVE-2022-32352 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient_admission. | ||
| CVE-2022-25004 | Cri | 0.64 | 9.8 | 0.02 | Feb 24, 2022 | Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php. | ||
| CVE-2022-25003 | Cri | 0.64 | 9.8 | 0.02 | Feb 24, 2022 | Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/view_doctor.php. | ||
| CVE-2022-22854 | Hig | 0.57 | 8.8 | 0.01 | Feb 14, 2022 | An access control issue in hprms/admin/?page=user/list of Hospital Patient Record Management System v1.0 allows attackers to escalate privileges via accessing and editing the user list. | ||
| CVE-2022-24232 | Hig | 0.51 | 7.8 | 0.02 | Feb 24, 2022 | A local file inclusion in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-32351 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_message. | ||
| CVE-2022-32350 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_room_type. | ||
| CVE-2022-32349 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient_history. | ||
| CVE-2022-32348 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_doctor. | ||
| CVE-2022-32347 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_room. | ||
| CVE-2022-32346 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/rooms/view_room.php?id=. | ||
| CVE-2022-32345 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/rooms/manage_room.php?id=. | ||
| CVE-2022-32344 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient. | ||
| CVE-2022-32343 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via hprms/admin/room_types/manage_room_type.php?id=. | ||
| CVE-2022-32342 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/room_types/view_room_type.php?id=. | ||
| CVE-2022-32341 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/?page=user/manage_user&id=. | ||
| CVE-2022-32340 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/?page=patients/view_patient&id=. | ||
| CVE-2022-32339 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/doctors/view_doctor.php?id=. | ||
| CVE-2022-32338 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/doctors/manage_doctor.php?id=. | ||
| CVE-2022-26244 | Med | 0.35 | 5.4 | 0.00 | Mar 30, 2022 | A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "special" field. | ||
| CVE-2022-22853 | Med | 0.35 | 5.4 | 0.01 | Feb 16, 2022 | A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the Name field. | ||
| CVE-2022-22852 | Med | 0.35 | 5.4 | 0.01 | Jan 26, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_list. | ||
| CVE-2022-22850 | Med | 0.35 | 5.4 | 0.01 | Jan 26, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_types. | ||
| CVE-2022-22296 | Med | 0.35 | 5.3 | 0.01 | Jan 24, 2022 | Sourcecodester Hospital's Patient Records Management System 1.0 is vulnerable to Insecure Permissions via the id parameter in manage_user endpoint. Simply change the value and data of other users can be displayed. | ||
| CVE-2022-22851 | Med | 0.00 | 5.4 | 0.01 | Jan 26, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the specialization parameter in doctors.php |
- risk 0.64cvss 9.8epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/patients/manage_patient.php?id=.
- risk 0.64cvss 9.8epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient_admission.
- risk 0.64cvss 9.8epss 0.02
Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php.
- risk 0.64cvss 9.8epss 0.02
Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/view_doctor.php.
- risk 0.57cvss 8.8epss 0.01
An access control issue in hprms/admin/?page=user/list of Hospital Patient Record Management System v1.0 allows attackers to escalate privileges via accessing and editing the user list.
- risk 0.51cvss 7.8epss 0.02
A local file inclusion in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_message.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_room_type.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient_history.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_doctor.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_room.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/rooms/view_room.php?id=.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/rooms/manage_room.php?id=.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via hprms/admin/room_types/manage_room_type.php?id=.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/room_types/view_room_type.php?id=.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/?page=user/manage_user&id=.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/?page=patients/view_patient&id=.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/doctors/view_doctor.php?id=.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/doctors/manage_doctor.php?id=.
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "special" field.
- risk 0.35cvss 5.4epss 0.01
A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the Name field.
- risk 0.35cvss 5.4epss 0.01
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_list.
- risk 0.35cvss 5.4epss 0.01
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_types.
- risk 0.35cvss 5.3epss 0.01
Sourcecodester Hospital's Patient Records Management System 1.0 is vulnerable to Insecure Permissions via the id parameter in manage_user endpoint. Simply change the value and data of other users can be displayed.
- risk 0.00cvss 5.4epss 0.01
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the specialization parameter in doctors.php