PT-2021-3396 · Unknown · Phpgurukul Hospital Management System
Published
2021-06-22
·
Updated
2023-11-14
·
CVE-2020-22167
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PHPGurukul Hospital Management System version 4.0
Description
The issue is related to a lack of protection for the web page structure in the
appointment-history.php component of the PHPGurukul Hospital Management System. This can be exploited by a remote attacker to intercept cookie data. The vulnerability is a Persistent Cross-Site Scripting issue that can be exploited by remote registered users to obtain user cookie data.Recommendations
For PHPGurukul Hospital Management System version 4.0, consider disabling access to the
appointment-history.php file until a patch is available to prevent exploitation of the Persistent Cross-Site Scripting vulnerability. Restrict access to the hms/admin directory to minimize the risk of exploitation. Avoid using the cookie data in the affected API endpoints until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpgurukul Hospital Management System