Impact
The vulnerability resides in the Guest Book module of HospitalManagement, where user‑supplied arguments nama, email and pesan are not properly escaped before being rendered. This allows an attacker who can submit data to that endpoint to inject arbitrary HTML or JavaScript into pages viewed by other users, a classic reflected XSS flaw mapped to CWE‑79 and a code‑evaluation issue reflected in CWE‑94. An attacker could use the injected script to steal session cookies, deface the site or redirect visitors to malicious destinations, thereby compromising confidentiality and integrity of user sessions.
Affected Systems
All instances of the HospitalManagement web application built from the repository up to commit c2d45543789a3887067d3915f69d44cfc2cf76a8 are affected. The project employs a rolling‑release continuous‑delivery model and does not publish discrete version numbers, so any deployment made before the mentioned commit is vulnerable.
Risk and Exploitability
The base CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, but an exploit has already been published, implying some exploitation activity may be occurring. The flaw can be triggered remotely via the web interface, meaning that an attacker does not need privileged access to the server. Because the impact is limited to injected script execution, the risk is lower than remote code execution but still significant for user data protection and brand integrity. The product is not listed in the CISA KEV catalog, but the existence of a public exploit warrants immediate attention.
OpenCVE Enrichment