Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 07 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stored Cross‑Site Scripting via User Name Field in PHPGurukal Hospital Management System v4.0 | |
| First Time appeared |
Phpgurukul
Phpgurukul hospital Management System |
|
| Vendors & Products |
Phpgurukul
Phpgurukul hospital Management System |
Thu, 07 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stored Cross‑Site Scripting via User Name Field in PHPGurukal Hospital Management System v4.0 |
Thu, 07 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Thu, 07 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This flaw allows an authenticated attacker (patient) to inject a malicious script payload into the User Name parameter, which is stored in the application and later rendered in the doctor s interface. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-07T15:41:03.902Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36388
Updated: 2026-05-07T15:40:56.526Z
Status : Deferred
Published: 2026-05-07T16:16:19.127
Modified: 2026-05-07T18:45:48.327
Link: CVE-2026-36388
No data.
OpenCVE Enrichment
Updated: 2026-05-07T18:00:12Z