shihjay2

2 exploits Active since Jan 2023
CVE-2023-24610 WRITEUP HIGH STUB
NOSH 4a5cfdb - Authenticated Remote Code Execution via Practice Logo Upload
NOSH 4a5cfdb allows remote authenticated users to execute PHP arbitrary code via the "practice logo" upload feature. The client-side checks can be bypassed. This may allow attackers to steal Protected Health Information because the product is for health charting.
CVSS 8.8
CVE-2023-24065 WRITEUP MEDIUM STUB
NOSH 4a5cfdb - Stored Cross-Site Scripting via Create User Page
NOSH 4a5cfdb allows stored XSS via the create user page. For example, a first name (of a physician, assistant, or billing user) can have a JavaScript payload that is executed upon visiting the /users/2/1 page. This may allow attackers to steal Protected Health Information because the product is for health charting.
CVSS 5.4