CVE-2021-25791 EXPLOIT
5.4
MEDIUM · CVSS 3.1 · EPSS 2.5% (pctl 84)
Patch early
A public exploit exists.
Description
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.
Scoring
| CVSS | 5.4 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 2.54% — more likely to be exploited than 84% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2021-07-23 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| online doctor appointment system php full source code project | online doctor appointment system php full source code |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Online Doctor Appointment System 1.0 - 'Multiple' Stored XSS | 2021-01-08 |
References
- https://www.exploit-db.com/exploits/49396
- https://www.sourcecodester.com
- https://www.sourcecodester.com/php/14663/online-doctor-appointment-system-php-full-source-code.html
- https://www.exploit-db.com/exploits/49396
- https://www.sourcecodester.com
- https://www.sourcecodester.com/php/14663/online-doctor-appointment-system-php-full-source-code.html
→ the Explorer · watch your stack · NVD