PT-2022-20141 · Unknown · Oretnom23 Automotive Shop Management System

N1_X

·

Published

2022-05-26

·

Updated

2022-06-03

·

CVE-2022-30494

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions oretnom23 Automotive Shop Management System version 1.0
Description The issue concerns a stored XSS Injection Vulnerability in the first and last name user fields, allowing remote attackers to gain admin access and view internal IPs.
Recommendations For oretnom23 Automotive Shop Management System version 1.0, consider temporarily restricting access to the first name and last name fields until a patch is available to prevent exploitation of the stored XSS Injection Vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-30494

Affected Products

Oretnom23 Automotive Shop Management System