CVE-2022-36203

Doctor's Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) via the admin panel. In addition, it leads to takeover the administrator account by stealing the cookie via XSS.
Configurations

Configuration 1 (hide)

cpe:2.3:a:doctor\'s_appointment_system_project:doctor\'s_appointment_system:1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-08-31 21:15

Updated : 2024-02-28 19:29


NVD link : CVE-2022-36203

Mitre link : CVE-2022-36203

CVE.ORG link : CVE-2022-36203


JSON object : View

Products Affected

doctor\'s_appointment_system_project

  • doctor\'s_appointment_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')