Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26627 | In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment. |
Tue, 16 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 08 Sep 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:phpgurukul:doctor_appointment_management_system:1.0.0:*:*:*:*:*:*:* |
Thu, 04 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phpgurukul
Phpgurukul doctor Appointment Management System |
|
| Vendors & Products |
Phpgurukul
Phpgurukul doctor Appointment Management System |
Wed, 03 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Wed, 03 Sep 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-16T16:28:17.980Z
Reserved: 2025-04-22T00:00:00.000Z
Link: CVE-2025-45805
Updated: 2025-09-03T18:34:55.608Z
Status : Modified
Published: 2025-09-03T18:15:34.910
Modified: 2025-12-16T17:16:08.277
Link: CVE-2025-45805
No data.
OpenCVE Enrichment
Updated: 2025-09-04T13:12:18Z
EUVD