CVE-2020-5191
MEDIUMNuclei
Hospital Management System 4.0 - Persistent Cross-Site Scripting
Record summary
CVE-2020-5191 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBHospital Management System 4.0 - Persistent Cross-Site ScriptingExploitDB exploitby FULLSHADENot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMPHPGurukul Hospital Management System - Cross-Site ScriptingCVSS 6.1
PHPGurukul Hospital Management System in PHP 4.0 contains multiple cross-site scripting vulnerabilities. An attacker can execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
WeaknessesCWE-79
AuthorsTenBird
Template tagscve2020cvehmscmsxssauthenticatededbphpgurukulvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:phpgurukul:hospital_management_system:4.0:*:*:*:*:*:*:*
Shodan: http.html:"hospital management system"
FOFA: body="hospital management system"
https://www.exploit-db.com/exploits/47841 https://phpgurukul.com/hospital-management-system-in-php/ https://nvd.nist.gov/vuln/detail/CVE-2020-5191 https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-5191 phpgurukul.com
https://phpgurukul.com/hospital-management-system-in-php exploit-db.com
https://www.exploit-db.com/exploits/47841