CVE-2020-36011
MEDIUMQDOCS Smart Hospital Management System 3.1 - Stored Cross-Site Scripting via Add Patient Form
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-36011. PoCs published by Kislay Kumar.
AI-analyzed exploit summary This is a technical writeup detailing a stored XSS vulnerability in Smart Hospital 3.1. It provides step-by-step instructions to exploit the vulnerability by injecting malicious payloads into patient profile fields, which execute when viewed.
Description
A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbitrary code via the Name, Guardian Name, Email, Address, Remarks, or Any Known Allergies field.
Exploits (1)
This is a technical writeup detailing a stored XSS vulnerability in Smart Hospital 3.1. It provides step-by-step instructions to exploit the vulnerability by injecting malicious payloads into patient profile fields, which execute when viewed.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N