Lucene search

K

Hospital Information Management Security Vulnerabilities

cve
cve

CVE-2024-23747

The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. This vulnerability resides in the system's handling of user data access through a /Modernanet/LAUDO/LAU0000100/Laudo?id= URI. By manipulating this id...

7.5CVSS

7.4AI Score

0.001EPSS

2024-01-29 02:15 PM
11
cve
cve

CVE-2020-26627

A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under the 'Contact Us Queries -> Unread Query'...

4.9CVSS

5.4AI Score

0.0005EPSS

2024-01-10 09:15 AM
11
cve
cve

CVE-2020-26630

A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an...

4.9CVSS

5.5AI Score

0.0005EPSS

2024-01-10 09:15 AM
13
cve
cve

CVE-2023-31498

A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code and access sensitive information via the session token...

9.8CVSS

9.6AI Score

0.018EPSS

2023-05-11 11:15 AM
15
cve
cve

CVE-2022-26546

Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive information and obtain the admin...

9.1CVSS

9.1AI Score

0.002EPSS

2022-03-31 09:15 PM
52
cve
cve

CVE-2021-36352

Stored cross-site scripting (XSS) vulnerability in Care2x Hospital Information Management 2.7 Alpha. The vulnerability has found POST requests in /modules/registration_admission/patient_register.php page with "name_middle", "addr_str", "station", "name_maiden", "name_2", "name_3"...

5.4CVSS

5.2AI Score

0.001EPSS

2021-08-26 02:15 PM
22
cve
cve

CVE-2021-36351

SQL Injection Vulnerability in Care2x Open Source Hospital Information Management 2.7 Alpha via the (1) pday, (2) pmonth, and (3) pyear parameters in GET requests sent to...

9.8CVSS

9.7AI Score

0.006EPSS

2021-08-06 02:15 PM
36
4
cve
cve

CVE-2020-22170

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive...

7.5CVSS

7.7AI Score

0.025EPSS

2021-06-22 03:15 PM
18
cve
cve

CVE-2020-22171

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\registration.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive...

7.5CVSS

7.7AI Score

0.025EPSS

2021-06-22 03:15 PM
19
cve
cve

CVE-2020-22172

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive...

7.5CVSS

7.7AI Score

0.025EPSS

2021-06-22 03:15 PM
14
2
cve
cve

CVE-2020-22173

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive...

7.5CVSS

7.7AI Score

0.025EPSS

2021-06-22 03:15 PM
16
2
cve
cve

CVE-2020-22174

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive...

7.5CVSS

7.7AI Score

0.025EPSS

2021-06-22 03:15 PM
15
3
cve
cve

CVE-2020-22168

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive...

7.5CVSS

7.7AI Score

0.007EPSS

2021-06-22 03:15 PM
16
cve
cve

CVE-2020-22169

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\appointment-history.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive...

7.5CVSS

7.7AI Score

0.025EPSS

2021-06-22 03:15 PM
16
cve
cve

CVE-2020-22175

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive...

7.5CVSS

7.7AI Score

0.025EPSS

2021-06-22 03:15 PM
19
2
cve
cve

CVE-2020-22176

PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive...

7.5CVSS

7.2AI Score

0.007EPSS

2021-06-22 03:15 PM
16
2
cve
cve

CVE-2020-22166

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\forgot-password.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive...

7.5CVSS

7.7AI Score

0.025EPSS

2021-06-22 03:15 PM
16
cve
cve

CVE-2020-22165

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive...

7.5CVSS

7.7AI Score

0.025EPSS

2021-06-22 03:15 PM
20
cve
cve

CVE-2020-22164

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive...

7.5CVSS

7.7AI Score

0.025EPSS

2021-06-22 03:15 PM
21
cve
cve

CVE-2020-5192

PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully...

8.8CVSS

9AI Score

0.384EPSS

2020-01-06 01:15 AM
109