Record summary

CVE-2020-36011 has a selected CVSS score of 4.8 (medium); EIP currently links 1 catalogued exploit.

Description

A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbitrary code via the Name, Guardian Name, Email, Address, Remarks, or Any Known Allergies field.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBSmart Hospital 3.1 - _Add Patient_ Stored XSSExploitDB exploitby Kislay KumarNot analyzed1 file
ExploitDB

PoC details

References

3