312
VMScore

CVE-2021-25791

Published: 23/07/2021 Updated: 03/08/2021
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated malicious users to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

online doctor appointment system php full source code project online doctor appointment system php full source code 1.0

Github Repositories

Multiple Stored XSS Online Doctor Appointment System

CVE-2021-25791-Multiple-Stored-XSS : Multiple Stored XSS Online Doctor Appointment System Multiple stored aunthenticated cross-site scripting exists in the Online Doctor Appointment System V10 Software Link: wwwsourcecodestercom/download-code?nid=14663&title=Online+Doctor+Appointment+System+in+PHP+with+Full+Source+Code cvemitreorg/cgi-bin/cvenamecg