PT-2024-37501 · Sourcecodester · Clinic Queuing System

R0Ck3T

·

Published

2024-06-23

·

Updated

2024-09-17

·

CVE-2024-6273

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: SourceCodester Clinic Queuing System version 1.0
Description: A vulnerability was found in the Clinic Queuing System, affecting the function save patient of the file patient side.php. The manipulation of the arguments Full Name, Contact, and Address leads to cross-site scripting. The attack can be launched remotely. The input fields Full Name, Contact, and Address do not sanitize user input, which leads to stored cross-site scripting.
Recommendations: As a temporary workaround, consider disabling the save patient function in the patient side.php file until a patch is available. Restrict access to the input fields Full Name, Contact, and Address to minimize the risk of exploitation. Avoid using these fields in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-6273

Affected Products

Clinic Queuing System