HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.
HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php.
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php.
HMS v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via treatmentrecord.php.
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doctor parameter at /admin-panel1…
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpassword parameter at /admin-pan…
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1…
HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php.
An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files.
SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php.
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through prescribe.php.
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.
Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php.