ZeroHour

CVE-2025-65270

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p21
Published
()
Modified
Description

Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote attacker to execute JavaScript code in the context of the victim's browser.

Vendors
clincapture
Products
captivate electronic data capture
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.