CVE-2025-45805: Phpgurukul Doctor Appointment Management System

High severity, CVSS 7.6. EPSS: 0.4% chance of exploitation in the next 30 days.

In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment.

Affected products

  • Phpgurukul Doctor Appointment Management System: version 1.0.0 only

Published 2025-09-03. Last modified 2026-06-17.