Cross-Site Request Forgery Vulnerability in PHPGurukul Hospital Management System
CVE-2025-70062
6.5MEDIUM
What is CVE-2025-70062?
The PHPGurukul Hospital Management System v4.0 is susceptible to a Cross-Site Request Forgery (CSRF) flaw within its 'Add Doctor' functionality. The lack of CSRF token validation at the add-doctor.php endpoint allows remote attackers to exploit this vulnerability. By crafting a malicious webpage, attackers can trick authenticated administrators into executing unwanted actions, such as creating unauthorized doctor accounts with privileged access.
