CVE-2025-41003 describes a stored Cross-Site Scripting (XSS) vulnerability in Imaster's Patient Record Management System, specifically within the ‘/projects/hospital/admin/edit_patient.php’ endpoint. An authenticated attacker can inject malicious JavaScript into the ‘firstname’ parameter, which is then stored and executed whenever a user views the patient list. This allows for arbitrary JavaScript execution in a victim's browser, potentially leading to session hijacking or data manipulation. The vulnerability has a CVSS score of 5.1 (MEDIUM), indicating a network-based attack with low attack complexity, requiring user interaction. While the impact on confidentiality, integrity, and availability is considered low, successful exploitation could compromise user sessions. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) or community discussion has been observed for this CVE. It is not listed on the CISA KEV catalog or any hot lists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Imaster | Patient Record Management System | All versionsCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.