EIP-2026-107627
PRE-CVEHospitals Patient Records Management System 1.0 - 'room_types' Stored Cross Site Scripting (XSS)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107627. PoCs published by Sant268.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Hospitals Patient Records Management System 1.0, where an attacker can inject malicious JavaScript via the 'description' parameter in the 'room_types' page. The payload triggers when the page is accessed, executing arbitrary JavaScript in the context of the victim's browser.
Description
Hospitals Patient Records Management System 1.0 - 'room_types' Stored Cross Site Scripting (XSS)
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Hospitals Patient Records Management System 1.0, where an attacker can inject malicious JavaScript via the 'description' parameter in the 'room_types' page. The payload triggers when the page is accessed, executing arbitrary JavaScript in the context of the victim's browser.