CVE-2018-18705: Phptpoint Hospital Management System

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

PhpTpoint hospital management system suffers from multiple SQL injection vulnerabilities via the index.php user parameter associated with LOGIN.php, or the rno parameter to ALIST.php, DUNDEL.php, PDEL.php, or PUNDEL.php.

Affected products

  • Phptpoint Hospital Management System: version 1.0 only

Published 2018-10-29. Last modified 2026-06-17.