CVE-2022-36203

Doctor's Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) via the admin panel. In addition, it leads to takeover the administrator account by stealing the cookie via XSS.
Configurations

Configuration 1 (hide)

cpe:2.3:a:doctor\'s_appointment_system_project:doctor\'s_appointment_system:1.0:*:*:*:*:*:*:*

History

06 Sep 2022, 17:36

Type Values Removed Values Added
References (MISC) http://packetstormsecurity.com/files/168211/Doctors-Appointment-System-1.0-Cross-Site-Scripting.html - (MISC) http://packetstormsecurity.com/files/168211/Doctors-Appointment-System-1.0-Cross-Site-Scripting.html - Exploit, Third Party Advisory, VDB Entry
References (MISC) https://www.sourcecodester.com/hashenudara/simple-doctors-appointment-project.html - (MISC) https://www.sourcecodester.com/hashenudara/simple-doctors-appointment-project.html - Product
References (MISC) https://github.com/aznull/CVEs - (MISC) https://github.com/aznull/CVEs - Third Party Advisory
First Time Doctor\'s Appointment System Project doctor\'s Appointment System
Doctor\'s Appointment System Project
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:a:doctor\'s_appointment_system_project:doctor\'s_appointment_system:1.0:*:*:*:*:*:*:*

01 Sep 2022, 18:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/168211/Doctors-Appointment-System-1.0-Cross-Site-Scripting.html -

31 Aug 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-31 21:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-36203

Mitre link : CVE-2022-36203

CVE.ORG link : CVE-2022-36203


JSON object : View

Products Affected

doctor\'s_appointment_system_project

  • doctor\'s_appointment_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')