PT-2022-18129 · Sourcecodester · Sourcecodester Wedding Hall Booking System

Published

2022-08-06

·

Updated

2022-08-11

·

CVE-2022-2692

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Wedding Hall Booking System (affected versions not specified)
Description A vulnerability was found in the SourceCodester Wedding Hall Booking System, affecting an unknown part of the file /whbs/admin/?page=user of the component Staff User Profile. The manipulation of the First Name and Last Name arguments leads to cross-site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-2692

Affected Products

Sourcecodester Wedding Hall Booking System