PT-2022-26312 · Unknown · Phpgurukul Hospital Management System

Riccardo Nannini

·

Published

2022-10-21

·

Updated

2025-05-08

·

CVE-2022-42206

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHPGurukul Hospital Management System version 4.0
Description The issue concerns a Cross Site Scripting (XSS) vulnerability. It affects the "doctor/view-patient.php", "admin/view-patient.php", and "view-medhistory.php" endpoints.
Recommendations For PHPGurukul Hospital Management System version 4.0, update the software to a version that includes a fix for this issue, if available. As a temporary workaround, consider restricting access to the affected endpoints until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-42206

Affected Products

Phpgurukul Hospital Management System