PT-2021-21247 · Unknown · Care2X Hospital Information Management

Published

2021-08-26

·

Updated

2021-09-01

·

CVE-2021-36352

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Care2x Hospital Information Management version 2.7 Alpha
Description A stored cross-site scripting (XSS) issue has been identified. The vulnerability is found in POST requests to the "/modules/registration admission/patient register.php" page, specifically with the parameters name middle, addr str, station, name maiden, name 2, and name 3.
Recommendations For Care2x Hospital Information Management version 2.7 Alpha, consider disabling the parameters name middle, addr str, station, name maiden, name 2, and name 3 in the "/modules/registration admission/patient register.php" page as a temporary workaround until a patch is available. Restrict access to the patient registration module to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36352

Affected Products

Care2X Hospital Information Management