ClinicCases 7.3.3 is susceptible to multiple reflected cross-site scripting vulnerabilities that could allow unauthenticated attackers to introduce arbitrary JavaScript by crafting a malicious URL. This can result in account takeover via session token theft.
id: CVE-2021-38704
info:
name: ClinicCases 7.3.3 Cross-Site Scripting
author: alph4byt3
sever
...