← Volver a CVEs
CVE-2022-36668
MEDIUM5.4
Descripcion
Garage Management System 1.0 is vulnerable to Stored Cross Site Scripting (XSS) on several parameters. The vulnerabilities exist during creating or editing the parts under parameters. Using the XSS payload, the Stored XSS triggered and can be used for further attack vector.
Detalles CVE
Puntuacion CVSS v3.15.4
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioREQUIRED
Publicado9/14/2022
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
garage_management_system_project:garage_management_system
Debilidades (CWE)
CWE-79
Referencias
https://github.com/saitamang/POC-DUMP/blob/main/Garage%20Management%20System/README.md(cve@mitre.org)
https://www.sourcecodester.com/php/15485/garage-management-system-using-phpmysql-source-code.html(cve@mitre.org)
https://github.com/saitamang/POC-DUMP/blob/main/Garage%20Management%20System/README.md(af854a3a-2127-422b-91ae-364da2661108)
https://www.sourcecodester.com/php/15485/garage-management-system-using-phpmysql-source-code.html(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.