S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Oct 15, 2025

CVE-2021-39411 Scanner

CVE-2021-39411 Scanner - Cross-Site Scripting (XSS) vulnerability in Hospital Management System

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-39411
6.1
CVSS

Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searchdata parameter in (a) doctor/search.php and (b) admin/patient-search.php, and the (2) fromdate and (3) todate parameters in admin/betweendates-detailsreports.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Hospital Management System is a software application designed to streamline and simplify the operations in healthcare facilities. It is utilized by hospitals, clinics, and other medical institutions to manage patient information, appointments, billing, and other administrative tasks. Medical professionals and administrative staff rely on these systems for efficient management of daily activities, ensuring that patient care is prioritized. The software is versatile enough to cater to various departments within a hospital, providing comprehensive data access to authorized personnel. With its integration capabilities, it can connect with other medical systems for an improved workflow. Overall, its primary aim is to improve the quality of healthcare services by enhancing operational efficiency.

The Cross-Site Scripting (XSS) vulnerability in web applications allows attackers to inject malicious scripts into web pages. In the case of Hospital Management System 1.0, this vulnerability can be exploited via the searchdata parameter in doctor/search.php and patient-search.php endpoints. XSS vulnerabilities typically occur when an application takes user input and renders it without proper validation or escaping. This vulnerability can lead to the execution of scripts in the victim's browser, often in the context of the application. It can result in data theft, session hijacking, and redirection to malicious sites. As such, it poses significant security risks if left unaddressed.

In technical terms, the vulnerability is a straightforward Cross-Site Scripting (XSS) flaw within the Hospital Management System 1.0. The software does not sufficiently sanitize user input in the searchdata parameter, allowing an attacker to inject and execute arbitrary scripts. This is evidenced through endpoints such as /hms/doctor/search.php and /hms/admin/patient-search.php. The vulnerability can be triggered by sending a crafted POST request with a payload, like , resulting in script execution within the target user's session context. A successful attack requires that the server responds with HTTP status code 200 and outputs the injected script, indicating a failure in input validation mechanisms.

Exploitation of this XSS vulnerability can have significant impacts. An attacker could execute malicious scripts to steal sensitive information, such as session cookies, which may lead to unauthorized access to user accounts. Phishing attacks could be orchestrated by altering the content displayed to users. Additionally, it could be used to spread malware or redirect users to malicious websites. This vulnerability undermines the trust of users in the application and compromises the confidentiality and integrity of the system.

REFERENCES

Solution Advice
  • Implement proper input validation for user-submitted data.
  • Utilize output encoding to prevent execution of injected scripts.
  • Regularly update software to ensure vulnerabilities are patched.
  • Conduct security audits to identify and address other potential vulnerabilities.
  • Educate users on recognizing phishing attacks and suspicious activities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.