PT-2023-11750 · Unknown · Hospital Management System
CVE-2020-26628
·
Publicado
2023-12-27
·
Atualizado
2024-01-16
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Hospital Management System version 4.0
Description
A Cross-Site Scripting (XSS) vulnerability was discovered in the Hospital Management System, allowing an attacker to execute arbitrary web scripts or HTML code via a malicious payload appended to a
username on the 'Edit Profile' page and triggered by another user visiting the profile.Recommendations
For Hospital Management System version 4.0, consider disabling the 'Edit Profile' page functionality until a patch is available to prevent exploitation of the XSS vulnerability. Restrict access to the 'Edit Profile' page to minimize the risk of arbitrary web script execution. Avoid using the
username field in the 'Edit Profile' page until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Hospital Management System