CVE-2020-5191
MEDIUM NUCLEIPHPGurukul Hospital Management System 4.0 - Stored Cross-Site Scripting
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-5191. PoCs published by FULLSHADE. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in Hospital Management System 4.0 via the 'doctorspecilization' parameter. The payload is injected via POST request and stored in the application, triggering when viewed.
Description
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in Hospital Management System 4.0 via the 'doctorspecilization' parameter. The payload is injected via POST request and stored in the application, triggering when viewed.
Nuclei Templates (1)
http.html:"hospital management system"
body="hospital management system"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N