CVE-2023-24065
MEDIUMNOSH 4a5cfdb - Stored Cross-Site Scripting via Create User Page
Title source: llmDescription
NOSH 4a5cfdb allows stored XSS via the create user page. For example, a first name (of a physician, assistant, or billing user) can have a JavaScript payload that is executed upon visiting the /users/2/1 page. This may allow attackers to steal Protected Health Information because the product is for health charting.
References (5)
Core 5
Core References
Third Party Advisory
https://gist.github.com/abbisQQ/e0967d5b8355087c8e224bdd1ace3bf3
Exploit, Third Party Advisory
https://github.com/shihjay2/nosh2/issues/202
Third Party Advisory
https://github.com/shihjay2/nosh2/tree/4a5cfdbd73f6a2ab5ee43a33d173c46fe0271533
Product, Third Party Advisory
https://noshemr.wordpress.com
Scores
CVSS v3
5.4
EPSS
0.0057
EPSS Percentile
42.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
nosh_chartingsystem_project/nosh_chartingsystem
Published
Jan 29, 2023
Tracked Since
Feb 18, 2026