CVE-2021-38704
07.09.2021, 20:15
Multiple reflected cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow unauthenticated attackers to introduce arbitrary JavaScript by crafting a malicious URL. This can result in account takeover via session token theft.
Vendor | Product | Version |
---|---|---|
cliniccases | cliniccases | 7.3.3 |
𝑥
= Vulnerable software versions