CVE-2025-65270
MEDIUMClinCapture EDC 3.0 and 2.2.3 - Unauthenticated Reflected Cross-Site Scripting
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-65270. PoCs published by xh4vm.
AI-analyzed exploit summary This repository provides a proof-of-concept for CVE-2025-65270, a reflected XSS vulnerability in ClinCapture EDC 3.0 and 2.2.3. The exploit demonstrates how an unauthenticated attacker can inject JavaScript via the 'name' or 'email' parameters in the password recovery functionality.
Description
Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote attacker to execute JavaScript code in the context of the victim's browser.
Exploits (1)
This repository provides a proof-of-concept for CVE-2025-65270, a reflected XSS vulnerability in ClinCapture EDC 3.0 and 2.2.3. The exploit demonstrates how an unauthenticated attacker can inject JavaScript via the 'name' or 'email' parameters in the password recovery functionality.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N