Vulnerability Description
Doctor's Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) via the admin panel. In addition, it leads to takeover the administrator account by stealing the cookie via XSS.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Doctor\'S Appointment System Project | Doctor\'S Appointment System | 1.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/168211/Doctors-Appointment-System-1.0-CrossExploitThird Party AdvisoryVDB Entry
- https://github.com/aznull/CVEsThird Party Advisory
- https://www.sourcecodester.com/hashenudara/simple-doctors-appointment-project.htProduct
- http://packetstormsecurity.com/files/168211/Doctors-Appointment-System-1.0-CrossExploitThird Party AdvisoryVDB Entry
- https://github.com/aznull/CVEsThird Party Advisory
- https://www.sourcecodester.com/hashenudara/simple-doctors-appointment-project.htProduct
FAQ
What is CVE-2022-36203?
CVE-2022-36203 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Doctor's Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) via the admin panel. In addition, it leads to takeover the administrator account by stealing the cookie via XSS.
How severe is CVE-2022-36203?
CVE-2022-36203 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-36203?
Check the references section above for vendor advisories and patch information. Affected products include: Doctor\'S Appointment System Project Doctor\'S Appointment System.