CVE-2025-70062
PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fails to enforce CSRF token validation on the add-doctor.php endpoint. This allows remote attackers to create arbitrary Doctor accounts (privileged users) by tricking an authenticated administrator into visiting a malicious page.
Vendor
Product
CWE
Yayın Tarihi
2026-02-18 19:21:42
Güncelleme
2026-02-23 21:03:09
Source Identifier
cve@mitre.org
KEV Date Added
-