PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fails to enforce CSRF token validation on the add-doctor.php endpoint. This allows remote attackers to create arbitrary Doctor accounts (privileged users) by tricking an authenticated administrator into visiting a malicious page.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 | |
| Metrics |
cvssV3_1
|
Wed, 18 Feb 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fails to enforce CSRF token validation on the add-doctor.php endpoint. This allows remote attackers to create arbitrary Doctor accounts (privileged users) by tricking an authenticated administrator into visiting a malicious page. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-18T19:41:02.963Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70062
Updated: 2026-02-18T19:39:26.210Z
Status : Received
Published: 2026-02-18T19:21:42.270
Modified: 2026-02-18T20:18:31.377
Link: CVE-2025-70062
No data.
OpenCVE Enrichment
No data.