CVE-2025-7148: CodeAstro Simple Hospital Management System POST Parameter patient.html cross site scripting
A vulnerability was found in CodeAstro Simple Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /patient.html of the component POST Parameter Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Multiple parameters might be affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7148?
CVE-2025-7148 is classified as a problematic vulnerability due to its potential for cross site scripting.
Which software is affected by CVE-2025-7148?
CVE-2025-7148 affects CodeAstro Simple Hospital Management System version 1.0.
How does CVE-2025-7148 impact the system?
CVE-2025-7148 allows attackers to manipulate POST parameters leading to cross site scripting risks.
How do I fix CVE-2025-7148?
Fixing CVE-2025-7148 involves sanitizing inputs in the affected /patient.html file to prevent cross site scripting.
What type of vulnerability is CVE-2025-7148?
CVE-2025-7148 is a cross site scripting (XSS) vulnerability.