CVE-2022-25409: XSS
Published Feb 28, 2022
·Updated
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.
Affected Software
1 affected component
Hospital Management System Project Hospital Management System=1.0
Event History
Feb 28, 2022
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-25409?
The severity of CVE-2022-25409 is medium (5.4).
2
How can I exploit the stored cross-site scripting (XSS) vulnerability in Hospital Management System v1.0 (CVE-2022-25409)?
We do not provide information on how to exploit vulnerabilities.
3
How do I fix the stored cross-site scripting (XSS) vulnerability in Hospital Management System v1.0 (CVE-2022-25409)?
Upgrade to a patched version of Hospital Management System v1.0 or apply the relevant security patch provided by the vendor.
4
Is there a public reference for CVE-2022-25409?
Yes, you can find more information about CVE-2022-25409 at the following reference: https://github.com/kishan0725/Hospital-Management-System/issues/20
5
What is the CWE category associated with CVE-2022-25409?
CVE-2022-25409 is associated with CWE category 79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').