Vulnerability Description
Stored cross-site scripting (XSS) vulnerability in Care2x Hospital Information Management 2.7 Alpha. The vulnerability has found POST requests in /modules/registration_admission/patient_register.php page with "name_middle", "addr_str", "station", "name_maiden", "name_2", "name_3" parameters.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Care2X | Hospital Information Management | 2.7 |
Related Weaknesses (CWE)
References
- https://securityforeveryone.com/blog/care2x-hospital-information-management-systThird Party Advisory
- https://www.exploit-db.com/exploits/50197ExploitThird Party AdvisoryVDB Entry
- https://securityforeveryone.com/blog/care2x-hospital-information-management-systThird Party Advisory
- https://www.exploit-db.com/exploits/50197ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2021-36352?
CVE-2021-36352 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Stored cross-site scripting (XSS) vulnerability in Care2x Hospital Information Management 2.7 Alpha. The vulnerability has found POST requests in /modules/registration_admission/patient_register.php p...
How severe is CVE-2021-36352?
CVE-2021-36352 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-36352?
Check the references section above for vendor advisories and patch information. Affected products include: Care2X Hospital Information Management.