Impact
The system contains a reflected XSS flaw in the editPatient.php script, where an attacker can manipulate the id parameter to inject malicious JavaScript. This defect can be triggered remotely without authentication and leads to the execution of arbitrary code in the victim's browser, allowing session hijacking, data theft, or defacement. The vulnerability is classified under CWE‑79.
Affected Systems
The flaw is present in code‑projects Hospital Information System version 1.0, specifically in the Patient Management component within editPatient.php. Only this version of the product is known to be affected.
Risk and Exploitability
The CVSS score of 5.1 labels the vulnerability as medium severity, while the EPSS score is not available, leaving the exact exploitation probability uncertain. The flaw is not listed in the CISA KEV catalog, suggesting limited known widespread exploitation. The attack can be launched over the network from any host capable of reaching the vulnerable endpoint, making it a genuine remote threat.
OpenCVE Enrichment