CVE-2022-25409 β€” Cross-site Scripting in Management System Project Hospital Management System

Severity
5.4MEDIUMNVD
EPSS
0.2%
top 58.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 28
Latest updateMar 2

Description

Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

πŸ”΄Vulnerability Details

2
GHSA
GHSA-xw5j-4h78-77h2: Hospital Management System v1β†—2022-03-02
β–Ά
CVEList
CVE-2022-25409: Hospital Management System v1β†—2022-02-28
β–Ά
CVE-2022-25409 β€” Cross-site Scripting | cvebase