Cross-Site Scripting Vulnerability in PHPGurukul Hospital Management System
CVE-2024-56997

4.2MEDIUM

Key Information:

Vendor
PHPGurukul
Vendor
CVE Published:
21 January 2025

Summary

The PHPGurukul Hospital Management System 4.0 is susceptible to a Cross Site Scripting (XSS) vulnerability located in the '/doctor/index.php' page. This vulnerability arises when input is not properly sanitized, allowing attackers to inject malicious scripts via the 'Email' parameter. Successful exploitation of this flaw can lead to unauthorized actions and data exposure, emphasizing the necessity of secure coding practices and prompt updates to maintain system integrity.

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.