PT-2021-18581 · Unknown · Remote Clinic
Saud-Ahmad
·
Published
2021-04-12
·
Updated
2021-08-27
·
CVE-2021-30042
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Remote Clinic version 2.0
Description
The issue is related to Cross Site Scripting (XSS) that can be exploited via the
Clinic Name, Clinic Address, Clinic City, or Clinic Contact field on the "clinics/register.php" API endpoint. This allows for malicious script execution.Recommendations
For Remote Clinic version 2.0, as a temporary workaround, consider validating and sanitizing user input for the
Clinic Name, Clinic Address, Clinic City, and Clinic Contact fields to prevent XSS attacks. Restrict access to the "clinics/register.php" endpoint until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Remote Clinic