Show filters
57 Total Results
Displaying 41-50 of 57
Sort by:
Attacker Value
Unknown

CVE-2022-27420

Disclosure Date: May 04, 2022 (last updated October 07, 2023)
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.
Attacker Value
Unknown

CVE-2022-27413

Disclosure Date: May 03, 2022 (last updated October 07, 2023)
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php.
Attacker Value
Unknown

CVE-2022-27299

Disclosure Date: April 26, 2022 (last updated October 07, 2023)
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php.
Attacker Value
Unknown

CVE-2022-26546

Disclosure Date: March 31, 2022 (last updated February 23, 2025)
Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive information and obtain the admin password.
Attacker Value
Unknown

CVE-2022-24136

Disclosure Date: March 31, 2022 (last updated February 23, 2025)
Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php. To exploit, an attacker can upload any PHP file, and then execute it.
Attacker Value
Unknown

CVE-2022-25493

Disclosure Date: March 15, 2022 (last updated February 23, 2025)
HMS v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via treatmentrecord.php.
Attacker Value
Unknown

CVE-2022-25492

Disclosure Date: March 15, 2022 (last updated February 23, 2025)
HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php.
Attacker Value
Unknown

CVE-2022-25491

Disclosure Date: March 15, 2022 (last updated February 23, 2025)
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php.
Attacker Value
Unknown

CVE-2022-25490

Disclosure Date: March 15, 2022 (last updated February 23, 2025)
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.
Attacker Value
Unknown

CVE-2022-25409

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.