PT-2022-11720 · Unknown · Chikista Patient Management

Published

2022-03-31

·

Updated

2024-02-14

·

CVE-2021-42868

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Chikista Patient Management Software version 2.0.2
Description A Cross Site Scripting (XSS) issue exists in the first name parameter in several pages, including "patient/insert", "patient report", "appointment report", "visit report", and "bill detail report".
Recommendations For Chikista Patient Management Software version 2.0.2, consider disabling the first name parameter in the affected pages until a patch is available. Restrict access to the vulnerable pages to minimize the risk of exploitation. Avoid using the first name parameter in the affected API endpoints until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-42868

Affected Products

Chikista Patient Management