CVE-2025-45805: Phpgurukul Doctor Appointment Management System
High severity, CVSS 7.6. EPSS: 0.4% chance of exploitation in the next 30 days.
In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment.
Affected products
- Phpgurukul Doctor Appointment Management System: version 1.0.0 only
Published 2025-09-03. Last modified 2026-06-17.