CVE-2020-36011: Qdocs Smart Hospital
Medium severity, CVSS 4.8. EPSS: 0.7% chance of exploitation in the next 30 days.
A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbitrary code via the Name, Guardian Name, Email, Address, Remarks, or Any Known Allergies field.
Affected products
- Qdocs Smart Hospital: version 3.1 only
Published 2021-01-26. Last modified 2026-07-09.