CVE-2025-65270
MEDIUMClincapture Captivate Electronic Data Capture - XSS
Title source: ruleDescription
Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote attacker to execute JavaScript code in the context of the victim's browser.
Exploits (1)
Scores
CVSS v3
6.1
EPSS
0.0011
EPSS Percentile
29.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
clincapture/captivate_electronic_data_capture
2.2.3
clincapture/captivate_electronic_data_capture
3.0
Published
Dec 22, 2025
Tracked Since
Feb 18, 2026