vendor:
Online Clinic Management System
by:
Rafael Pedrero
7.5
CVSS
HIGH
Stored Cross-Site Scripting and Reflected Cross-Site Scripting
79
CWE
Product Name: Online Clinic Management System
Affected Version From: 2.2
Affected Version To: 2.2
Patch Exists: YES
Related CWE:
CPE: a:bigprof:online_clinic_management_system:2.2
Platforms Tested: Windows 7 64 Bits / Windows 10 64 Bits
2019
Online Clinic Management System 2.2 – Multiple Stored Cross-Site Scripting (XSS)
Online Clinic Management System 2.2, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scripting (XSS) vulnerability via the /clinic/medical_records_view.php, in FirstRecord parameter, GET and POST request and Reflected Cross-Site Scripting (XSS) vulnerability via the /clinic/events_view.php, in FirstRecord parameter and Reflected Cross-Site Scripting (XSS) vulnerability via the /clinic/disease_syndromes_view.php, in FirstRecord parameter.
Mitigation:
Encode user-controlled inputs to prevent XSS attacks.