CVE-2025-65270

MEDIUM

ClinCapture EDC 3.0 and 2.2.3 - Unauthenticated Reflected Cross-Site Scripting

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-65270. PoCs published by xh4vm.

AI-analyzed exploit summary This repository provides a proof-of-concept for CVE-2025-65270, a reflected XSS vulnerability in ClinCapture EDC 3.0 and 2.2.3. The exploit demonstrates how an unauthenticated attacker can inject JavaScript via the 'name' or 'email' parameters in the password recovery functionality.

Description

Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote attacker to execute JavaScript code in the context of the victim's browser.

Exploits (1)

nomisec WORKING POC
by xh4vm · poc
https://github.com/xh4vm/CVE-2025-65270

This repository provides a proof-of-concept for CVE-2025-65270, a reflected XSS vulnerability in ClinCapture EDC 3.0 and 2.2.3. The exploit demonstrates how an unauthenticated attacker can inject JavaScript via the 'name' or 'email' parameters in the password recovery functionality.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: ClinCapture EDC 3.0 and 2.2.3
No auth needed
Prerequisites: Access to the target application's password recovery page
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory
https://github.com/xh4vm/CVE-2025-65270

Scores

CVSS v3 6.1
EPSS 0.0025
EPSS Percentile 15.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
clincapture/captivate_electronic_data_capture 2.2.3
clincapture/captivate_electronic_data_capture 3.0
Published Dec 22, 2025
Tracked Since Feb 18, 2026