Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vulnerability. The application fails to verify that the requested 'viewid' parameter belongs to the currently authenticated patient. This allows a user to access the confidential medical records of other patients by iterating the 'viewid' integer.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHPGurukul Hospital Management System 安全漏洞
Vulnerability Description
PHPGurukul Hospital Management System是PHPGurukul公司的一套基于PHP和MySQL的医院管理系统。 PHPGurukul Hospital Management System v4.0版本存在安全漏洞,该漏洞源于Medical History模块未验证viewid参数归属,可能导致用户访问其他患者的机密医疗记录。
CVSS Information
N/A
Vulnerability Type
N/A