Description
A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/adminviews.py of the component Admin Dashboard Page. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Published: 2026-01-28
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

A flaw discovered in the admin views file of PHPGurukul Hospital Management System 1.0 allows attackers to bypass authorization checks, leading to unauthorized access to administrative functions. The vulnerability resides in adminviews.py and can be exploited remotely through crafted HTTP requests. It falls under CWE‑266 (Improper Privilege Management) and CWE‑285 (Improper Authorization).

Affected Systems

The affected product is PHPGurukul Hospital Management System version 1.0, released by vendor PHPGurukul. The flaw appears in the component managing admin pages, specifically the /hms/hospital/docappsystem/adminviews.py endpoint. No additional vendor or OS details are provided, and the scope appears limited to the admin dashboard functionality.

Risk and Exploitability

The CVSS v3.1 score of 5.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation so far. However, the vulnerability is remotely exploitable and an exploit has already been released to the public, meaning attackers can potentially use it to gain privileged access. The vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is through unauthorized HTTP requests to the admin views endpoint, so an attacker who can reach the web application could use the flaw to elevate privileges or manipulate sensitive data.

Generated by OpenCVE AI on April 18, 2026 at 01:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify that the PHPGurukul Hospital Management System version is 1.0 or earlier and contact the vendor for an update or patch.
  • Restrict the admin dashboard endpoints to authorized users only, enforcing strong authentication and role‑based access controls to mitigate until a vendor patch is available.
  • Configure a Web Application Firewall or security rule to block suspicious requests targeting the /adminviews.py endpoint, or limit access by IP address.

Generated by OpenCVE AI on April 18, 2026 at 01:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:phpgurukul:hospital_management_system:*:*:*:*:*:*:*:*

Mon, 09 Feb 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:phpgurukul:hospital_management_system:1.0:*:*:*:*:*:*:*

Thu, 29 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 29 Jan 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Phpgurukul
Phpgurukul hospital Management System
Vendors & Products Phpgurukul
Phpgurukul hospital Management System

Wed, 28 Jan 2026 23:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/adminviews.py of the component Admin Dashboard Page. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Title PHPGurukul Hospital Management System Admin Dashboard adminviews.py improper authorization
Weaknesses CWE-266
CWE-285
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Phpgurukul Hospital Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T09:03:01.284Z

Reserved: 2026-01-28T16:55:20.754Z

Link: CVE-2026-1550

cve-icon Vulnrichment

Updated: 2026-01-29T15:58:37.084Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-28T23:15:51.067

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-1550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T01:45:33Z

Weaknesses