CVE-2025-63513

k

ishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality.

Configurations

Configuration 1 (hide)

cpe:2.3:a:kishan0725:hospital_management_system:4.0:*:*:*:*:*:*:*

History

20 Nov 2025, 21:57

Type Values Removed Values Added
CPE cpe:2.3:a:kishan0725:hospital_management_system:4.0:*:*:*:*:*:*:*
References () https://github.com/NicatAliyevh/Zero-Days/blob/main/Hospital_Management_System_IDOR.md - () https://github.com/NicatAliyevh/Zero-Days/blob/main/Hospital_Management_System_IDOR.md - Exploit, Third Party Advisory
References () https://github.com/kishan0725/Hospital-Management-System/issues/55 - () https://github.com/kishan0725/Hospital-Management-System/issues/55 - Issue Tracking, Vendor Advisory
First Time Kishan0725 hospital Management System
Kishan0725

19 Nov 2025, 17:15

Type Values Removed Values Added
CWE CWE-639
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://github.com/kishan0725/Hospital-Management-System/issues/55 - () https://github.com/kishan0725/Hospital-Management-System/issues/55 -

18 Nov 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-18 17:16

Updated : 2025-11-20 21:57


NVD link : CVE-2025-63513

Mitre link : CVE-2025-63513

CVE.ORG link : CVE-2025-63513


JSON object : View

CWE
CWE-639

Authorization Bypass Through User-Controlled Key