PT-2022-23896 · Unknown · Crime Reporting System
Published
2022-09-06
·
Updated
2022-09-09
·
CVE-2022-37253
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Crime Reporting System version 1.0
Description
The issue allows a remote attacker to introduce arbitrary Javascript via manipulation of an unsanitized POST parameter, enabling persistent cross-site scripting (XSS) attacks.
Recommendations
For Crime Reporting System version 1.0, as a temporary workaround, consider sanitizing the POST parameter to prevent the introduction of malicious Javascript code. Restrict access to the affected module to minimize the risk of exploitation. Avoid using the vulnerable parameter in the affected API endpoint until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crime Reporting System