ClinicCases 7.3.3 is susceptible to multiple reflected cross-site scripting vulnerabilities that could allow unauthenticated attackers to introduce arbitrary JavaScript by crafting a malicious URL. This can result in account takeover via session token theft.
View the template here CVE-2021-38704.yaml
References:
https://github.com/ARPSyndicate/cvemon