Details
-
Technical task
-
Status: Approved
-
Must
-
Resolution: Fixed
-
None
-
Low
-
Ref App 2.11 Release Sprint 3, Ref App 2.12 Priorities
Description
This xss bug can be exploited when a user clicks on the "Visit Note" link on a patient's page and creates a note with diagnosis: Non-coded <script>alert('xss');</script>.
The injected JS will be executed back on the patient's page in the diagnosis section.