Cross Site Scripting Vulnerability in Clinic's Patient Management System by OnetNom23
CVE-2022-36251
6.1MEDIUM
Key Information:
- Vendor
- CVE Published:
- 22 August 2022
What is CVE-2022-36251?
The Clinic's Patient Management System version 1.0 is susceptible to a Cross Site Scripting (XSS) vulnerability through a flaw in the patients.php file. This allows an attacker to inject malicious scripts into the web application, potentially compromising sensitive patient information and jeopardizing the integrity of the system.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
