📦

hospital_management_system_in_php

Vendor: projectworlds

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 1 Remote Access
Total CVEs 7 Total Indexed
Avg. EPSS 1.12% Exploit Prob.
Latest CVE CVE-2023-5053 Sep 28

Security Vulnerability Index

Page 1 / 1
9.8 CVSS

Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.

EPSS: 0.90%
9.8 CVSS

Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.

EPSS: 0.90%
5.3 CVSS

An issue was discovered in Projectworlds Hospital Management System v1.0. Unauthorized malicious attackers can add patients without restriction via add_patient.php.

EPSS: 0.67%
9.8 CVSS

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php.

EPSS: 1.13%
8.8 CVSS

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an authenticated malicious user can compromise the databases system and in some cases leverage this vulnerability to get remote code execution on the remote web server.

EPSS: 2.00%
9.8 CVSS

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.

EPSS: 1.13%
9.8 CVSS

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.

EPSS: 1.13%