peter bassill · operator
$ cve CVE-2021-25791 JSON

CVE-2021-25791 EXPLOIT

5.4
MEDIUM · CVSS 3.1 · EPSS 2.5% (pctl 84)

Patch early

A public exploit exists.

Description

Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.

Scoring

CVSS5.4 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS2.54% — more likely to be exploited than 84% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2021-07-23
Last modified2026-06-17

Affected (1)

VendorProduct
online doctor appointment system php full source code projectonline doctor appointment system php full source code

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD