PT-2022-24343 · Unknown · Slims Senayan Library Management System

0Xdc9

·

Published

2022-09-12

·

Updated

2022-09-15

·

CVE-2022-38291

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SLiMS Senayan Library Management System version 9.4.2
Description The issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search function. This enables the execution of malicious code on the client-side, potentially leading to unauthorized actions or data exposure.
Recommendations For SLiMS Senayan Library Management System version 9.4.2, consider disabling the Search function until a patch is available to prevent exploitation of the cross-site scripting vulnerability. Restrict access to the Search bar to minimize the risk of malicious payload injection. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-38291

Affected Products

Slims Senayan Library Management System