Stored XSS permitting session takeover of arbitrary user
Vulnerability Description
Stored XSS vulnerability exists in the "Oddział" (Ward) module, in the death diagnosis description field, and allows the execution of arbitrary JavaScript code. This can lead to session hijacking of other users and potentially to privilege escalation up to full administrative rights.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-30036
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Maciej Kazulak