An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is transmitted in the login.php query string.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.openbugbounty.org/incidents/228262/ | third party advisory exploit |
https://www.exploit-db.com/exploits/42042/ | exploit |