PT-2022-22980 · Unknown · Sourcecodester Simple Cold Storage Management System

Rsrahulsingh05

·

Published

2022-10-18

·

Updated

2023-12-28

·

CVE-2022-3587

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Simple Cold Storage Management System version 1.0
Description A vulnerability was found in the My Account component, where the manipulation of the First Name argument leads to cross-site scripting. The attack can be launched remotely.
Recommendations For SourceCodester Simple Cold Storage Management System version 1.0, consider restricting the input for the First Name argument to prevent cross-site scripting attacks until a patch is available.

Exploit

Fix

Improper Neutralization

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-3587

Affected Products

Sourcecodester Simple Cold Storage Management System