CVE-2022-36668

Garage Management System 1.0 is vulnerable to Stored Cross Site Scripting (XSS) on several parameters. The vulnerabilities exist during creating or editing the parts under parameters. Using the XSS payload, the Stored XSS triggered and can be used for further attack vector.
Configurations

Configuration 1 (hide)

cpe:2.3:a:garage_management_system_project:garage_management_system:1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:13

Type Values Removed Values Added
References () https://github.com/saitamang/POC-DUMP/blob/main/Garage%20Management%20System/README.md - Exploit, Third Party Advisory () https://github.com/saitamang/POC-DUMP/blob/main/Garage%20Management%20System/README.md - Exploit, Third Party Advisory
References () https://www.sourcecodester.com/php/15485/garage-management-system-using-phpmysql-source-code.html - Third Party Advisory () https://www.sourcecodester.com/php/15485/garage-management-system-using-phpmysql-source-code.html - Third Party Advisory

Information

Published : 2022-09-14 11:15

Updated : 2024-11-21 07:13


NVD link : CVE-2022-36668

Mitre link : CVE-2022-36668

CVE.ORG link : CVE-2022-36668


JSON object : View

Products Affected

garage_management_system_project

  • garage_management_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')