Vulnerability Description
In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpgurukul | Doctor Appointment Management System | 1.0.0 |
Related Weaknesses (CWE)
References
- https://github.com/mhsinj/CVE-2025-45805Third Party Advisory
- https://github.com/mohammed-alsaqqaf/CVE-2025-45805
- https://phpgurukul.com/doctor-appointment-management-system-using-php-and-mysqlProduct
FAQ
What is CVE-2025-45805?
CVE-2025-45805 is a vulnerability with a CVSS score of 7.6 (HIGH). In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper ...
How severe is CVE-2025-45805?
CVE-2025-45805 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-45805?
Check the references section above for vendor advisories and patch information. Affected products include: Phpgurukul Doctor Appointment Management System.