First published: Tue Jan 17 2023(Updated: )
IMPatienT before 1.5.2 allows stored XSS via onmouseover in certain text fields within a PATCH /modify_onto request to the ontology builder. This may allow attackers to steal Protected Health Information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Unistra Impatient | <1.5.2 | |
<1.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23637 is considered a high severity vulnerability due to its potential for stored XSS attacks that can compromise protected health information.
To fix CVE-2023-23637, upgrade to Impatient version 1.5.2 or later, which addresses the stored XSS vulnerability.
CVE-2023-23637 enables stored cross-site scripting (XSS) attacks via malicious input in specific text fields.
CVE-2023-23637 affects Impatient versions prior to 1.5.2.
CVE-2023-23637 can potentially allow attackers to steal protected health information (PHI) from the affected application.