XSS Vulnerability in HAPI FHIR Testpage Overlay by HAPI FHIR
CVE-2020-24301

6.1MEDIUM

Key Information:

Vendor

Hapifhir

Vendor
CVE Published:
8 October 2020

What is CVE-2020-24301?

The HAPI FHIR Testpage Overlay versions 5.0.0 and earlier contain a Cross-Site Scripting (XSS) vulnerability. This security flaw allows an attacker to craft a URL that executes arbitrary JavaScript code in the user’s browser. While primarily intended for testing purposes and not widely utilized in production environments, users should remain cautious, as exploitation could lead to malicious behavior leveraging the vulnerability. Refer to the GitHub issue for more information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.