CVE-2025-45805

Published
View on NVD ↗
CVSS v3
7.6
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment.

Poc Of CVE-2025-45805
GitHubGitHub
1