Vulnerabilities (CVE)

Filtered by vendor Oretnom23 Subscribe
Filtered by product Clinic\'s Patient Management System
Total 27 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-36609 1 Oretnom23 1 Clinic\'s Patient Management System 2026-06-17 N/A 9.8 CRITICAL
Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pms/update_patient.php.
CVE-2022-36270 1 Oretnom23 1 Clinic\'s Patient Management System 2026-06-17 N/A 9.8 CRITICAL
Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php.
CVE-2022-36251 1 Oretnom23 1 Clinic\'s Patient Management System 2026-06-17 N/A 6.1 MEDIUM
Clinic's Patient Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via patients.php.
CVE-2022-36242 1 Oretnom23 1 Clinic\'s Patient Management System 2026-06-17 N/A 9.8 CRITICAL
Clinic's Patient Management System v1.0 is vulnerable to SQL Injection via /pms/update_medicine.php?id=.
CVE-2022-35117 1 Oretnom23 1 Clinic\'s Patient Management System 2026-06-17 N/A 4.8 MEDIUM
Clinic's Patient Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via update_medicine_details.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Packing text box under the Update Medical Details module.
CVE-2022-2298 1 Oretnom23 1 Clinic\'s Patient Management System 2026-06-17 7.5 HIGH 7.3 HIGH
A vulnerability has been found in SourceCodester Clinics Patient Management System 2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pms/index.php of the component Login Page. The manipulation of the argument user_name with the input admin' or '1'='1 leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2022-2297 1 Oretnom23 1 Clinic\'s Patient Management System 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0. Affected is an unknown function of the file /pms/update_user.php?user_id=1. The manipulation of the argument profile_picture with the input <?php phpinfo();?> leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.