Imaster's Patient Record Management System contains a stored Cross-Site Scripting (XSS) vulnerability in the endpoint β/projects/hospital/admin/edit_patient.phpβ. By injecting a malicious script into the βfirstnameβ parameter, the JavaScript code is stored and executed every time a user accesses the patient list, allowing an attacker to execute arbitrary JavaScript in a victim's browser.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation1 reference(s) from NVD