PT-2022-15730 · Sourcecodester · Sourcecodester Hotel/Lodge Management System
Cyberthoth
·
Published
2022-07-12
·
Updated
2022-07-16
·
CVE-2022-2291
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SourceCodester Hotel Management System version 2.0
Description
A problem was found in the Search component, affecting the /ci hms/search file. The issue is related to the manipulation of the
search argument with a specific input, leading to cross-site scripting. This can be initiated remotely.Recommendations
For version 2.0, consider restricting access to the /ci hms/search endpoint until a fix is available. As a temporary workaround, avoid using the
search argument in the affected endpoint to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Hotel/Lodge Management System