DCKento/CVE-2021-40374

DCKento/CVE-2021-40374

Releases0
Stars2
Stored Cross-site Scripting in OpenEyes 3.5.1

CVE History

CVEPublishedCVSS v3CVSS v2
5.4 MEDIUM3.5 LOW

A stored cross-site scripting (XSS) vulnerability was identified in Apperta Foundation OpenEyes 3.5.1. Updating a patient's details allows remote attackers to inject arbitrary web script or HTML via the Address1 parameter. This JavaScript then executes when the patient profile is loaded, which could be used in a XSS attack.