kishan0725/Hospital-Management-System

kishan0725/Hospital-Management-System

Releases0
Stars736
Hospital Management System using php and mysql

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM

kishan0725 Hospital Management System has a Cross-Site Scripting (XSS) vulnerability in appsearch.php via the email parameter.

6.5 MEDIUM

kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality.

8.8 HIGH

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter in doctorsearch.php.

8.8 HIGH

Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the username1 and password2 parameters.

9.8 CRITICAL

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.

6.1 MEDIUM

Hospital Management System v4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in func2.php via the fname and lname parameters.

9.8 CRITICAL

Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters.

9.8 CRITICAL

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.

9.8 CRITICAL

Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters.

9.8 CRITICAL

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.

6.5 MEDIUM

Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the password2 parameter.

9.8 CRITICAL

SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on March 13, 2021), allows attackers to execute arbitrary commands via the contact and doctor parameters to /search.php.

9.8 CRITICAL7.5 HIGH

Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.

5.4 MEDIUM3.5 LOW

A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "special" field.

5.4 MEDIUM3.5 LOW

Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.

5.4 MEDIUM3.5 LOW

Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpassword parameter at /admin-panel1.php.

5.4 MEDIUM3.5 LOW

Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doctor parameter at /admin-panel1.php.

7.5 HIGH7.8 HIGH

Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.

9.8 CRITICAL7.5 HIGH

Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.

9.8 CRITICAL7.5 HIGH

SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php.

6.1 MEDIUM4.3 MEDIUM

Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.

6.1 MEDIUM4.3 MEDIUM

Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through prescribe.php.

5.3 MEDIUM5 MEDIUM

Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php.