Vulnerability Description
Persistent cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow low-privileged attackers to introduce arbitrary JavaScript to account parameters. The XSS payloads will execute in the browser of any user who views the relevant content. This can result in account takeover via session token theft.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cliniccases | Cliniccases | 7.3.3 |
Related Weaknesses (CWE)
References
- https://github.com/judsonmitchell/ClinicCases/releasesRelease NotesThird Party Advisory
- https://github.com/sudonoodle/CVE-2021-38707ExploitThird Party Advisory
- https://github.com/judsonmitchell/ClinicCases/releasesRelease NotesThird Party Advisory
- https://github.com/sudonoodle/CVE-2021-38707ExploitThird Party Advisory
FAQ
What is CVE-2021-38707?
CVE-2021-38707 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Persistent cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow low-privileged attackers to introduce arbitrary JavaScript to account parameters. The XSS payloads will execute in the ...
How severe is CVE-2021-38707?
CVE-2021-38707 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-38707?
Check the references section above for vendor advisories and patch information. Affected products include: Cliniccases Cliniccases.