Description
A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Problem types
Product status
Timeline
| 2026-02-07: | Advisory disclosed |
| 2026-02-07: | VulDB entry created |
| 2026-02-11: | VulDB entry last update |
Credits
yan1451 (VulDB User)
References
vuldb.com/?id.344882 (VDB-344882 | PHPGurukul Hospital Management System manage-users.php sql injection)
vuldb.com/?ctiid.344882 (VDB-344882 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.749592 (Submit #749592 | PHPGurukul Hospital Management System 4.0 SQL Injection)
github.com/Shaon-Xis/PHPGurukul-HMS-SQLi-PoC/tree/main
github.com/Shaon-Xis/PHPGurukul-HMS-SQLi-PoC/tree/main
phpgurukul.com/