CVE-2025-70063 - PHPGurukul Hospital Management System IDOR
CVE ID : CVE-2025-70063
Published : Feb. 18, 2026, 7:21 p.m. | 1 hour, 1 minute ago
Description : The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vulnerability. The application fails to verify that the requested 'viewid' parameter belongs to the currently authenticated patient. This allows a user to access the confidential medical records of other patients by iterating the 'viewid' integer.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Feb. 18, 2026, 7:21 p.m. | 1 hour, 1 minute ago
Description : The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vulnerability. The application fails to verify that the requested 'viewid' parameter belongs to the currently authenticated patient. This allows a user to access the confidential medical records of other patients by iterating the 'viewid' integer.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...