CVE-2022-25493: XSS
Published Mar 15, 2022
·Updated
HMS v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via treatmentrecord.php.
Affected Software
1 affected component
Hospital Management System Project Hospital Management System=1.0
Event History
Mar 15, 2022
CVE Published
via MITRE·05:36 PM
Data Sourced
via MITRE·05:36 PM
Description
Frequently Asked Questions
1
What is CVE-2022-25493?
CVE-2022-25493 is a reflected cross-site scripting (XSS) vulnerability in HMS v1.0 via treatmentrecord.php.
2
How severe is CVE-2022-25493?
CVE-2022-25493 has a severity value of 6.1, which is classified as medium.
3
How does CVE-2022-25493 affect HMS v1.0?
CVE-2022-25493 affects HMS v1.0 by allowing an attacker to execute malicious scripts in the context of a user's browser session.
4
How can I fix CVE-2022-25493?
To fix CVE-2022-25493, it is recommended to apply the latest patch or update provided by the Hospital Management System project.
5
Is there any reference available for CVE-2022-25493?
Yes, you can find reference information for CVE-2022-25493 at: [GitHub Discussion](https://github.com/kabirkhyrul/HMS/discussions/10).