Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
No solution has been reported at this time.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 13 Jan 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Imaster
Imaster patient Record Management System |
|
| Vendors & Products |
Imaster
Imaster patient Record Management System |
Mon, 12 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 12 Jan 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Imaster's Patient Record Management System contains a stored Cross-Site Scripting (XSS) vulnerability in the endpoint ‘/projects/hospital/admin/edit_patient.php’. By injecting a malicious script into the ‘firstname’ parameter, the JavaScript code is stored and executed every time a user accesses the patient list, allowing an attacker to execute arbitrary JavaScript in a victim's browser. | |
| Title | Multiple vulnerabilities in Imaster products Open configuration options | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-01-12T14:29:51.672Z
Reserved: 2025-04-16T09:08:41.550Z
Link: CVE-2025-41003
Updated: 2026-01-12T14:29:48.615Z
Status : Deferred
Published: 2026-01-12T14:16:01.920
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-41003
No data.
OpenCVE Enrichment
Updated: 2026-01-13T09:27:37Z