PT-2022-15730 · Sourcecodester · Sourcecodester Hotel/Lodge Management System

Cyberthoth

·

Published

2022-07-12

·

Updated

2022-07-16

·

CVE-2022-2291

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Hotel Management System version 2.0
Description A problem was found in the Search component, affecting the /ci hms/search file. The issue is related to the manipulation of the search argument with a specific input, leading to cross-site scripting. This can be initiated remotely.
Recommendations For version 2.0, consider restricting access to the /ci hms/search endpoint until a fix is available. As a temporary workaround, avoid using the search argument in the affected endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-2291

Affected Products

Sourcecodester Hotel/Lodge Management System