PT-2022-20125 · Unknown · Automotive Shop Management System
Published
2022-05-24
·
Updated
2022-05-28
·
CVE-2022-30458
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Automotive Shop Management System version 1.0
Description
The issue concerns a Cross Site Scripting (XSS) vulnerability. It can be exploited via the API endpoint "/asms/classes/Master.php?f=save product" using the
name variable.Recommendations
For Automotive Shop Management System version 1.0, consider restricting access to the "/asms/classes/Master.php?f=save product" endpoint until a patch is available. As a temporary workaround, avoid using the
name variable in this endpoint to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Automotive Shop Management System