PT-2025-35815 · Phpgurukul · Doctor Appointment Management System

Ayman Al-Hakimi

+2

·

Published

2025-09-03

·

Updated

2025-09-03

·

CVE-2025-45805

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions phpgurukul Doctor Appointment Management System version 1.0
Description An authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is rendered without proper sanitization when a user visits the website and selects the doctor to book an appointment.
Recommendations As a temporary workaround, consider restricting the characters allowed in the doctor's profile name field to prevent JavaScript code injection.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-45805

Affected Products

Doctor Appointment Management System