Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-45805 — PoC of CVE-2025-45805 | Kitploit
Tools/GitHubGitHub/mohammed-alsaqqaf/cve-2025-45805
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubmohammed-alsaqqaf/cve-2025-45805

CVE-2025-45805

PoC of CVE-2025-45805

View Repository
8 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-45805

Poc Of CVE-2025-45805 Affected Product: Doctor Appointment Management System Vendor: phpgurukul Version: 1.0 Vulnerability Type: Stored Cross-Site Scripting (XSS)

Description: An authenticated doctor user can inject arbitrary JavaScript code into the doctor profile field (name/employee ID). The malicious payload is then rendered without sanitization when a patient selects the doctor to book an appointment, leading to arbitrary script execution in the victim’s browser. This can result in account takeover, session hijacking, or cookie theft.

Impact: High severity (Account Takeover, Session Hijacking) Attack Vector: Remote (Stored XSS), victim must visit the booking page Discovered by: Mohammed Hayaf Al-Saqqaf & Ayman Al-Hakimi

Play

Download Tool