Edoc-doctor-appointment-system v1.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability at /patient/settings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field.
History

Thu, 11 Dec 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Hashenudara
Hashenudara edoc-doctor-appointment-system
CPEs cpe:2.3:a:edoc-doctor-appointment-system_project:edoc-doctor-appointment-system:1.0.1:*:*:*:*:*:*:* cpe:2.3:a:hashenudara:edoc-doctor-appointment-system:1.0.1:*:*:*:*:*:*:*
Vendors & Products Edoc-doctor-appointment-system Project
Edoc-doctor-appointment-system Project edoc-doctor-appointment-system
Hashenudara
Hashenudara edoc-doctor-appointment-system

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T10:07:34.457Z

Reserved: 2022-07-25T00:00:00

Link: CVE-2022-36548

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-08-26T21:15:09.190

Modified: 2025-12-11T16:42:56.493

Link: CVE-2022-36548

cve-icon Redhat

No data.