6.1
CVSSv3

CVE-2022-36203

Published: 31/08/2022 Updated: 06/09/2022
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Doctor's Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) via the admin panel. In addition, it leads to takeover the administrator account by stealing the cookie via XSS.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

doctor\\'s appointment system project doctor\\'s appointment system 1.0

Exploits

Doctor's Appointment System version 10 suffers from a cross site scripting vulnerability in registerphp Original discovery of cross site scripting in this version is attributed to Soham Bakore in February of 2021 ...

Github Repositories

a list of my CVEs

a list of my CVEs CVE-2022-36201 A Blind SQLi vulnerability was found in Doctor's Appointment System version 10 cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2022-36201 CVE-2022-36202 Doctor's Appointment System version 10 was affected by Improper Access Control vulnerability leads to privilege escalation cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2