CVE-2023-23637: Unistra Impatient

High severity, CVSS 7.6. EPSS: 0.6% chance of exploitation in the next 30 days.

IMPatienT before 1.5.2 allows stored XSS via onmouseover in certain text fields within a PATCH /modify_onto request to the ontology builder. This may allow attackers to steal Protected Health Information.

Affected products

  • Unistra Impatient: before 1.5.2 (fixed in 1.5.2)

Published 2023-01-17. Last modified 2026-06-17.