CVE-2025-70064
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-284
Control de acceso incorrecto
Fecha de publicación:
18/02/2026
Última modificación:
19/02/2026
Descripción
*** Pendiente de traducción *** PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor Management) by manually browsing to the /admin/ directory after authentication. This allows any self-registered user to takeover the application, view confidential logs, and modify system data.
Impacto
Puntuación base 3.x
8.80
Gravedad 3.x
ALTA



