Medium
CVSS 4.3
Overview
Cross-site scripting (XSS) vulnerability in login.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web script or HTML via the customerEmailAddress parameter.
Cross-site scripting (XSS) vulnerability in login.php in DRZES HMS 3.2 allows re...
Cross-site scripting (XSS) vulnerability in login.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web script or HTML via the customerEmailAddress parameter.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: