Cross-Site Scripting Vulnerability in kishan0725 Hospital Management System
CVE-2025-63514

6.1MEDIUM

Key Information:

Vendor

kishan0725

Vendor
CVE Published:
18 November 2025

What is CVE-2025-63514?

The kishan0725 Hospital Management System is impacted by a Cross-Site Scripting (XSS) vulnerability located in the appsearch.php file. This flaw arises from inadequate sanitization of the email parameter, which could allow an attacker to inject malicious scripts. If successfully exploited, this vulnerability may lead to unauthorized actions on behalf of users, potentially compromising sensitive information and disrupting services.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.