Doctor's Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) via the admin panel. In addition, it leads to takeover the administrator account by stealing the cookie via XSS.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/168211/Doctors-Appointment-System-1.0-Cross-Site-Scripting.html | Exploit Third Party Advisory VDB Entry |
https://github.com/aznull/CVEs | Third Party Advisory |
https://www.sourcecodester.com/hashenudara/simple-doctors-appointment-project.html | Product |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2022-08-31 21:15
Updated : 2024-02-28 19:29
NVD link : CVE-2022-36203
Mitre link : CVE-2022-36203
CVE.ORG link : CVE-2022-36203
JSON object : View
Products Affected
doctor\'s_appointment_system_project
- doctor\'s_appointment_system
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')