Cross-Site Scripting Vulnerability in code-projects Hospital Management System
CVE-2024-12983
Key Information:
- Vendor
- Code-projects
- Status
- Hospital Management System
- Vendor
- CVE Published:
- 27 December 2024
Badges
Summary
A cross-site scripting vulnerability has been identified in the Hospital Management System version 1.0, specifically located in the Edit Doctor Details Page at /hospital/hms/admin/manage-doctors.php. This vulnerability permits attackers to manipulate the Doctor Name input field, leading to potential remote exploitation through unauthorized script execution. Given that this flaw has been publicly disclosed, it poses a significant risk to users, highlighting the urgent need for patching and security enhancements. Additional parameters within the application could also be susceptible, necessitating a comprehensive security review.
Affected Version(s)
Hospital Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved