CVE-2022-25408 β€” Cross-site Scripting in Management System Project Hospital Management System

Severity
5.4MEDIUMNVD
EPSS
0.2%
top 58.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 28
Latest updateMar 2

Description

Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpassword parameter at /admin-panel1.php.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

πŸ”΄Vulnerability Details

2
GHSA
GHSA-rr9w-g73c-r4mq: Hospital Management System v1β†—2022-03-02
β–Ά
CVEList
CVE-2022-25408: Hospital Management System v1β†—2022-02-28
β–Ά
CVE-2022-25408 β€” Cross-site Scripting | cvebase