PT-2023-25560 · Unknown · Hospital Management System

Published

2023-07-10

·

Updated

2025-11-11

·

CVE-2023-36375

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hostel Management System version 2.1
Description The issue allows an attacker to execute arbitrary code through a crafted payload to parameters such as Guardian name, Guardian relation, complimentary address, city, permanent address, and city in the Book Hostel & Room Details page.
Recommendations For Hostel Management System version 2.1, consider restricting access to the Book Hostel & Room Details page until a fix is available, and avoid using the parameters Guardian name, Guardian relation, complimentary address, city, permanent address, and city in this page to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-36375

Affected Products

Hospital Management System