PT-2021-21247 · Unknown · Care2X Hospital Information Management
Published
2021-08-26
·
Updated
2021-09-01
·
CVE-2021-36352
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Care2x Hospital Information Management version 2.7 Alpha
Description
A stored cross-site scripting (XSS) issue has been identified. The vulnerability is found in POST requests to the "/modules/registration admission/patient register.php" page, specifically with the parameters
name middle, addr str, station, name maiden, name 2, and name 3.Recommendations
For Care2x Hospital Information Management version 2.7 Alpha, consider disabling the parameters
name middle, addr str, station, name maiden, name 2, and name 3 in the "/modules/registration admission/patient register.php" page as a temporary workaround until a patch is available. Restrict access to the patient registration module to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Care2X Hospital Information Management