PT-2022-22187 · Sourcecodester · Sourcecodester Book Store Management System

·

CVE-2022-3452

·

Published

2022-10-11

·

Updated

2022-10-11

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Book Store Management System version 1.0
Description A vulnerability was found in the SourceCodester Book Store Management System. It affects the file /category.php, where the manipulation of the category name argument leads to cross-site scripting. The attack can be initiated remotely.
Recommendations For SourceCodester Book Store Management System version 1.0, consider restricting access to the /category.php file until a fix is available. As a temporary workaround, avoid using the category name argument in the affected file to minimize the risk of exploitation.

Fix

Improper Neutralization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3452

Affected Products

Sourcecodester Book Store Management System