PT-2025-35815 · Phpgurukul · Doctor Appointment Management System
Ayman Al-Hakimi
+2
·
Published
2025-09-03
·
Updated
2025-09-03
·
CVE-2025-45805
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
phpgurukul Doctor Appointment Management System version 1.0
Description
An authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is rendered without proper sanitization when a user visits the website and selects the doctor to book an appointment.
Recommendations
As a temporary workaround, consider restricting the characters allowed in the doctor's profile name field to prevent JavaScript code injection.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Doctor Appointment Management System