Codeastro · Codeastro Hospital Management System · CVE-2025-7153
Name of the Vulnerable Software and Affected Versions:
CodeAstro Simple Hospital Management System version 1.0
Description:
A problematic issue was found in the CodeAstro Simple Hospital Management System, affecting an unknown functionality of the file /doctor.html, specifically the POST Parameter Handler component. The manipulation of the `First Name`, `Last Name`, or `Address` arguments leads to cross-site scripting. This issue can be exploited remotely.
Recommendations:
For CodeAstro Simple Hospital Management System version 1.0, as a temporary workaround, consider restricting access to the /doctor.html file until a patch is available. Avoid using the `First Name`, `Last Name`, or `Address` parameters in the affected POST Parameter Handler component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.