Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-45805 PoC — PHPGurukul Doctor Appointment Management System 安全漏洞

Source
Associated Vulnerability
Title: PHPGurukul Doctor Appointment Management System 安全漏洞 (CVE-2025-45805)
Description:In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment.
Description
Poc Of CVE-2025-45805
Readme
# CVE-2025-45805
Poc Of CVE-2025-45805
Affected Product: Doctor Appointment Management System
Vendor: phpgurukul
Version: 1.0
Vulnerability Type: Stored Cross-Site Scripting (XSS)

Description:
An authenticated doctor user can inject arbitrary JavaScript code into the doctor profile field (name/employee ID). The malicious payload is then rendered without sanitization when a patient selects the doctor to book an appointment, leading to arbitrary script execution in the victim’s browser. This can result in account takeover, session hijacking, or cookie theft.

Impact: High severity (Account Takeover, Session Hijacking)
Attack Vector: Remote (Stored XSS), victim must visit the booking page
Discovered by: Mohammed Hayaf Al-Saqqaf (BULLETMHS) & Ayman Al-Hakimi


[![Play](Screenshot_2025-09-02-23-41-56-09_f2cb81fb7cf38af7978f186f2a61634a.jpg)](ATO%20XSS.mp4)

File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →