CVE-2023-23637: Unistra Impatient
High severity, CVSS 7.6. EPSS: 0.6% chance of exploitation in the next 30 days.
IMPatienT before 1.5.2 allows stored XSS via onmouseover in certain text fields within a PATCH /modify_onto request to the ontology builder. This may allow attackers to steal Protected Health Information.
Affected products
- Unistra Impatient: before 1.5.2 (fixed in 1.5.2)
Published 2023-01-17. Last modified 2026-06-17.