Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 23 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:phpgurukul:hospital_management_system:4.0:*:*:*:*:*:*:* |
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phpgurukul
Phpgurukul hospital Management System |
|
| Vendors & Products |
Phpgurukul
Phpgurukul hospital Management System |
Wed, 18 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Wed, 18 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor Management) by manually browsing to the /admin/ directory after authentication. This allows any self-registered user to takeover the application, view confidential logs, and modify system data. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-18T19:32:55.774Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70064
Updated: 2026-02-18T19:31:07.298Z
Status : Analyzed
Published: 2026-02-18T19:21:42.493
Modified: 2026-02-23T21:03:37.660
Link: CVE-2025-70064
No data.
OpenCVE Enrichment
Updated: 2026-02-19T10:20:37Z