vendor:
Hospitals Patient Records Management System
by:
Sant268
7.5
CVSS
HIGH
Stored XSS
79
CWE
Product Name: Hospitals Patient Records Management System
Affected Version From: HPRMS 1.0
Affected Version To: HPRMS 1.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Ubuntu 20, Apache
2020
Hospitals Patient Records Management System 1.0 – ‘doctors’ Stored Cross Site Scripting (XSS)
A Stored XSS issue in HPRMS v.1.0 allows remote attackers to inject JavaScript via /articles in the description parameter.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.