PT-2021-17393 · Unknown · Doctor Appointment System
Published
2021-03-01
·
Updated
2021-03-08
·
CVE-2021-27317
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Doctor Appointment System version 1.0
Description
The issue allows remote attackers to inject arbitrary web script or HTML via the
comment parameter in the contactus.php file, potentially leading to unauthorized actions on the web application.Recommendations
For Doctor Appointment System version 1.0, consider validating and sanitizing user input for the
comment parameter to prevent injection of malicious scripts or HTML. As a temporary workaround, restrict access to the contactus.php file until a proper fix is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Doctor Appointment System