CVE-2024-2135 | Bdtask Hospital AutoManager up to 20240223 Hospital Activities Page form Description cross site scripting
A vulnerability labeled as problematic has been found in Bdtask Hospital AutoManager up to 20240223. Affected is an unknown function of the file /hospital_activities/birth/form of the component Hospital Activities Page. Executing manipulation of the argument Description with the input <img src=a onerror=alert(1)> can lead to cross site scripting.
This vulnerability is handled as CVE-2024-2135. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.