Record summary

CVE-2020-5191 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBHospital Management System 4.0 - Persistent Cross-Site ScriptingExploitDB exploitby FULLSHADENot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMPHPGurukul Hospital Management System - Cross-Site ScriptingCVSS 6.1

PHPGurukul Hospital Management System in PHP 4.0 contains multiple cross-site scripting vulnerabilities. An attacker can execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-79
AuthorsTenBird
Template tagscve2020cvehmscmsxssauthenticatededbphpgurukulvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:phpgurukul:hospital_management_system:4.0:*:*:*:*:*:*:*
Shodan: http.html:"hospital management system"
FOFA: body="hospital management system"

Source: ProjectDiscovery

References

3