CVE-2025-70064Disclosure(phpgurukul / hospital_management_system)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor Management) by manually browsing to the /admin/ directory after authentication. This allows any self-registered user to takeover the application, view confidential logs, and modify system data.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hospital_management_system

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
hospital_management_system

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-18: 2PoC Mentioned / Linked · 2026-02-18: 1Technical Details · 2026-02-18: 202-18
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-70064 PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashbo… https://www.cve.org/CVERecord?id=CVE-2025-70064

    Post summary

    The text announces a new privilege‑escalation vulnerability in PHPGurukul Hospital Management System v4.0, where low‑privileged users can directly access the administrator dashboard, with no mention of exploits, patches or active exploitation.

    00010422
    56.4K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-70064 - High PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (... https://www.thehackerwire.com/vulnerability/CVE-2025-70064/ https://t.co/6O6yvQot26

    Post summary

    PHPGurukul Hospital Management System v4.0 suffers from a privilege escalation vulnerability that lets low‑privileged patients access the admin dashboard, with details posted on TheHackerWire.

    0000039
    112 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphpgurukulhospital_management_system4.0--

Explore more