PT-2023-11750 · Unknown · Hospital Management System

Published

2023-12-27

·

Updated

2024-01-16

·

CVE-2020-26628

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hospital Management System version 4.0
Description A Cross-Site Scripting (XSS) vulnerability was discovered in the Hospital Management System, allowing an attacker to execute arbitrary web scripts or HTML code via a malicious payload appended to a username on the 'Edit Profile' page and triggered by another user visiting the profile.
Recommendations For Hospital Management System version 4.0, consider disabling the 'Edit Profile' page functionality until a patch is available to prevent exploitation of the XSS vulnerability. Restrict access to the 'Edit Profile' page to minimize the risk of arbitrary web script execution. Avoid using the username field in the 'Edit Profile' page until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-26628

Affected Products

Hospital Management System