CVE-2025-5584
Last modified
CVE-2025-5584 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been classified as problematic. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been classified as problematic. Affected is an unknown function of the file /doctor/edit-patient.php?editid=2 of the component POST Parameter Handler. The manipulation of the argument patname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Anujk305 | Hospital Management System | 4.0 |
References
- https://github.com/Ant1sec-ops/Hospital-management-Systemv4.0-Stored-XSS/blob/main/stored-xss-exploit.mdExploit, Third Party Advisory
- https://phpgurukul.com/Product
- https://vuldb.com/?ctiid.311046Permissions Required, VDB Entry
- https://vuldb.com/?id.311046Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.588828Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-5584?
How severe is CVE-2025-5584?
How do I fix CVE-2025-5584?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-55816HotelDruid v3.0.7 and before is vulnerable to Cross Site Scr…6.1
- CVE-2025-5582A vulnerability was found in CodeAstro Real Estate Managemen…9.8
- CVE-2025-55824ModStartCMS v9.5.0 has an arbitrary file write vulnerability…6.5
- CVE-2025-5583A vulnerability classified as critical has been found in Cod…9.8
- CVE-2025-55834A Cross Site Scripting vulnerability in JeeWMS v.3.7 and bef…6.1
- CVE-2025-55835File Upload vulnerability in SueamCMS v.0.1.2 allows a remot…9.8
- CVE-2025-55847Wavlink M86X3A_V240730 contains a buffer overflow vulnerabil…8.8
- CVE-2025-55848An issue was discovered in DIR-823 firmware 20250416. There …8.8
- CVE-2025-55849WeiPHP v5.0 and before is vulnerable to SQL Injection via th…8.4
- CVE-2025-5585The SiteOrigin Widgets Bundle plugin for WordPress is vulner…5.4
- CVE-2025-55852Tenda AC8 v16.03.34.06 is vulnerable to Buffer Overflow in t…7.5
- CVE-2025-55853SoftVision webPDF before 10.0.2 is vulnerable to Server-Side…9.1
Are you affected by CVE-2025-5584?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
