Hospital Management System
cpe:2.3:a:hospital_management_system_project:hospital_management_system:*:*:*:*:*:*:*
- v4
Multiple cross-site scripting (XSS) vulnerabilities have been identified in Hospital Management System version 4. These vulnerabilities reside in the 'func2.php' file, where the 'fname' and 'lname' parameters are not properly sanitized. This lack of sanitation allows remote attackers to inject and execute arbitrary scripts in the context of the victim's browser.
Exploitation of these vulnerabilities allows for cross-site scripting, where injected scripts are executed in the context of the user's browser.
To reproduce this vulnerability, log into the Hospital Management System and navigate to a feature that utilizes the 'func2.php' file. Inject a script into the 'fname' or 'lname' parameters. The absence of proper input validation will allow the script to execute, demonstrating the cross-site scripting vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.