Cross-site Scripting vulnerability in BigProf products
Vulnerability Description
A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /clinic/disease_symptoms_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous JavaScript payloads on the system that will be triggered when the page loads.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-6424
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Rafael Pedrero
References
More from BigProf
View All →Affected Vendor
BigProf
View all reports →