Doctor's Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) via the admin panel. In addition, it leads to takeover the administrator account by stealing the cookie via XSS.
References
Link | Resource |
---|---|
https://www.sourcecodester.com/hashenudara/simple-doctors-appointment-project.html | Product |
https://github.com/aznull/CVEs | Third Party Advisory |
http://packetstormsecurity.com/files/168211/Doctors-Appointment-System-1.0-Cross-Site-Scripting.html | Exploit Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-08-31 14:15
Updated : 2022-09-06 10:36
NVD link : CVE-2022-36203
Mitre link : CVE-2022-36203
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
doctor\'s_appointment_system_project
- doctor\'s_appointment_system