PT-2022-23847 · Sourcecodester · Sourcecodester Online Medicine Ordering System
Namit13
·
Published
2022-10-27
·
Updated
2023-12-28
·
CVE-2022-3716
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SourceCodester Online Medicine Ordering System version 1.0
Description
A problematic issue was found in the system, affecting an unknown functionality of the file /omos/admin/?page=user/list. The manipulation of the
First Name, Middle Name, and Last Name arguments leads to cross-site scripting. The attack can be launched remotely.Recommendations
For SourceCodester Online Medicine Ordering System version 1.0, consider restricting access to the /omos/admin/?page=user/list endpoint until a fix is available. As a temporary workaround, avoid using the
First Name, Middle Name, and Last Name arguments in this endpoint to minimize the risk of exploitation.Fix
Improper Neutralization
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sourcecodester Online Medicine Ordering System