vendor:
Bayanno Hospital Management System
by:
Gokhan Sagoglu
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: Bayanno Hospital Management System
Affected Version From: 4.0
Affected Version To: 4.0
Patch Exists: NO
Related CWE: N/A
CPE: a:creativeitem:bayanno_hospital_management_system
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2018
Bayanno Hospital Management System 4.0 – Cross-Site Scripting
Due to improper user input management and lack of output encoding, unauthenticated users are able to inject malicious code via making an appointment. Malicious code runs on admin panel.
Mitigation:
Input validation and output encoding should be implemented to prevent XSS attacks.