Cross-Site Scripting Flaw in Doctor Appointment Management System by PHP Gurukul
CVE-2022-45730

6.1MEDIUM

Key Information:

Vendor
PHPgurukul
Vendor
CVE Published:
26 January 2023

Summary

The vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to exploit a cross-site scripting flaw. By injecting a malicious payload into the Search function, an attacker can execute arbitrary web scripts or HTML. This can lead to the unauthorized disclosure of sensitive information or the hijacking of user sessions. It is crucial for users of this system to be aware of this risk and apply necessary security measures.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.