mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-31 18:50:38 +00:00
751 B
751 B
CVE-2022-29940
Description
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_popup.php leads to multiple cross-site scripting (XSS) vulnerabilities.
POC
Reference
- https://nitroteam.kz/index.php?action=researches&slug=librehealth_r
- https://nitroteam.kz/index.php?action=researches&slug=librehealth_r
Github
No PoCs found on GitHub currently.