cve/2020/CVE-2020-35745.md
2024-05-25 21:48:12 +02:00

880 B

CVE-2020-35745

Description

PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.

POC

Reference

Github