Home

Description

Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote attacker to execute JavaScript code in the context of the victim's browser.

PUBLISHED Reserved 2025-11-18 | Published 2025-12-22 | Updated 2025-12-23 | Assigner mitre

References

github.com/xh4vm/CVE-2025-65270 exploit

www.clincapture.com/

github.com/xh4vm/CVE-2025-65270

cve.org (CVE-2025-65270)

nvd.nist.gov (CVE-2025-65270)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.