PT-2021-18579 · Unknown · Remote Clinic
Saud-Ahmad
·
Published
2021-04-12
·
Updated
2021-08-27
·
CVE-2021-30039
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Remote Clinic version 2.0
Description
The issue is related to Cross Site Scripting (XSS) that can be exploited via the
Fever or Blood Pressure field on the "patients/register-report.php" API endpoint. This allows for malicious script execution.Recommendations
For Remote Clinic version 2.0, as a temporary workaround, consider restricting input for the
Fever and Blood Pressure fields in the "patients/register-report.php" endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Remote Clinic