Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-35745

Опубликовано: 07 янв. 2021
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:phpgurukul:hospital_management_system:4.0:*:*:*:*:*:*:*

EPSS

Процентиль: 59%
0.00379
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.

EPSS

Процентиль: 59%
0.00379
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-862