CVE Details
Basic Information
| Title | CodeAstro Patient Record Management System Generate New Report Page cross site scripting |
|---|---|
| Type | cve |
| Published | 2025-06-22T02:00:10.742Z |
| Last Seen |
Product Information
| Vendor | CodeAstro |
|---|---|
| Product | Patient Record Management System |
| Version | 1.0 |
CVSS Information
| Base Score | 4.8 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A cross-site scripting (XSS) vulnerability in CodeAstro’s Patient Record Management System allows remote attackers to inject malicious scripts via the Patient Name field. This could lead to session hijacking or unauthorized data access. The vulnerability is considered medium severity due to its potential impact on sensitive healthcare data. |
|---|---|
| AI Severity | Medium |
| Vendor | CodeAstro |
| Product | Patient Record Management System |
| Affected Version | 1.0 |
Affected Products
- CodeAstro Patient Record Management System 1.0
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-79, CWE-94 |
| Bulletin Family |
References
- https://vuldb.com/?id.313559
- https://vuldb.com/?ctiid.313559
- https://vuldb.com/?submit.598711
- https://github.com/Vanshdhawan188/CodeAstro-Online-Healthcare-Patient-Record-Management-System/blob/main/CodeAstro-Online-Healthcare-Patient-Record-Management-System.md
- https://github.com/Vanshdhawan188/CodeAstro-Online-Healthcare-Patient-Record-Management-System/blob/main/CodeAstro-Online-Healthcare-Patient-Record-Management-System.md#-proof-of-concept-poc
- https://codeastro.com/
Description
A vulnerability was found in CodeAstro Patient Record Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the component Generate New Report Page. The manipulation of the argument Patient Name/Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.