PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.
References
Link | Resource |
---|---|
https://medium.com/@ashketchum/privilege-escalation-unauthenticated-access-to-admin-portal-cve-2020-35745-bb5d5dca97a0 | Exploit Third Party Advisory |
https://www.youtube.com/watch?v=vnSsg6iwV9Y&feature=youtu.be&ab_channel=ashketchum | Exploit Third Party Advisory |
https://www.phpgurukul.com/hospital-management-system-in-php/ | Product Third Party Advisory |
Configurations
Information
Published : 2021-01-07 13:15
Updated : 2021-07-21 04:39
NVD link : CVE-2020-35745
Mitre link : CVE-2020-35745
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
phpgurukul
- hospital_management_system_in_php