Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-05858
HistorySep 09, 2021 - 12:00 a.m.

ClinicCases Cross-Site Scripting Vulnerability (CNVD-2022-05858)

2021-09-0900:00:00
China National Vulnerability Database
www.cnvd.org.cn
6

0.001 Low

EPSS

Percentile

21.4%

ClinicCases is an open source case management system designed for law school clinics.A cross-site scripting vulnerability exists in ClinicCases version 7.3.3, which stems from a lack of effective validation and filtering of user-submitted parameters by the software. The vulnerability allows a low privilege attacker to introduce arbitrary JavaScript to set account parameters. the XSS payload will execute in the browser of any user viewing the content in question. An attacker could take over the account through session token theft.

CPENameOperatorVersion
cliniccases cliniccaseseq7.3.3

0.001 Low

EPSS

Percentile

21.4%

Related for CNVD-2022-05858