PT-2022-23537 · Unknown · Garage Management System

Saitamang

·

Published

2022-09-14

·

Updated

2022-09-16

·

CVE-2022-36668

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Garage Management System version 1.0
Description The issue is related to Stored Cross Site Scripting (XSS) that occurs on several parameters during the creation or editing of parts. This can be triggered using an XSS payload, allowing for further attack vectors.
Recommendations For Garage Management System version 1.0, consider restricting access to the parameters involved in creating or editing parts until a fix is available. As a temporary workaround, avoid using the vulnerable parameters during these operations to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-36668

Affected Products

Garage Management System