vendor:
Hospitals Patient Records Management System
by:
Sant268
8.8
CVSS
HIGH
Stored Cross Site Scripting (XSS)
79
CWE
Product Name: Hospitals Patient Records Management System
Affected Version From: HPRMS 1.0
Affected Version To: HPRMS 1.0
Patch Exists: NO
Related CWE:
CPE: a:sourcecodester:hospitals_patient_records_management_system:1.0
Platforms Tested: Ubuntu 20, Apache
2020
Hospitals Patient Records Management System 1.0 – ‘room_list’ Stored Cross Site Scripting (XSS)
A XSS issue in HPRMS v.1.0 allows remote attackers to inject JavaScript via /articles in the description parameter.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.