CVE-2025-70062

PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fails to enforce CSRF token validation on the add-doctor.php endpoint. This allows remote attackers to create arbitrary Doctor accounts (privileged users) by tricking an authenticated administrator into visiting a malicious page.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgurukul:hospital_management_system:4.0:*:*:*:*:*:*:*

History

23 Feb 2026, 21:03

Type Values Removed Values Added
CPE cpe:2.3:a:phpgurukul:hospital_management_system:4.0:*:*:*:*:*:*:*
First Time Phpgurukul hospital Management System
Phpgurukul
References () https://gist.github.com/Sanka1pp/78795abd84220e879ee0425159af5ae2 - () https://gist.github.com/Sanka1pp/78795abd84220e879ee0425159af5ae2 - Exploit
References () https://packetstorm.news/files/id/213711 - () https://packetstorm.news/files/id/213711 - Exploit, Mitigation, Third Party Advisory
Summary
  • (es) PHPGurukul Hospital Management System v4.0 contiene una vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en el módulo 'Add Doctor'. La aplicación no aplica la validación de tokens CSRF en el endpoint add-doctor.php. Esto permite a atacantes remotos crear cuentas de Doctor arbitrarias (usuarios privilegiados) engañando a un administrador autenticado para que visite una página maliciosa.

18 Feb 2026, 20:18

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-352

18 Feb 2026, 19:21

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-18 19:21

Updated : 2026-02-23 21:03


NVD link : CVE-2025-70062

Mitre link : CVE-2025-70062

CVE.ORG link : CVE-2025-70062


JSON object : View

Products Affected

phpgurukul

  • hospital_management_system
CWE
CWE-352

Cross-Site Request Forgery (CSRF)