CVE-2022-3587 – SourceCodester Simple Cold Storage Management System My Account cross site scripting
https://notcve.org/view.php?id=CVE-2022-3587
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component My Account. The manipulation of the argument First Name leads to cross site scripting. The attack can be launched remotely. • https://github.com/rsrahulsingh05/POC/blob/main/Stored%20XSS https://vuldb.com/?id.211201 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-707: Improper Neutralization •
CVE-2022-3580 – SourceCodester Cashier Queuing System User Creation cross site scripting
https://notcve.org/view.php?id=CVE-2022-3580
A vulnerability, which was classified as problematic, has been found in SourceCodester Cashier Queuing System 1.0.1. This issue affects some unknown processing of the component User Creation Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-211187. • https://vuldb.com/?id.211187 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-707: Improper Neutralization •
CVE-2022-3579 – SourceCodester Cashier Queuing System Login Page login.php sql injection
https://notcve.org/view.php?id=CVE-2022-3579
A vulnerability classified as critical was found in SourceCodester Cashier Queuing System 1.0. This vulnerability affects unknown code of the file /queuing/login.php of the component Login Page. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/DisguisedRoot/Exploit/blob/main/SQLInj/POC https://vuldb.com/?id.211186 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE-707: Improper Neutralization •
CVE-2022-3549 – SourceCodester Simple Cold Storage Management System Avatar unrestricted upload
https://notcve.org/view.php?id=CVE-2022-3549
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /csms/admin/?page=user/manage_user of the component Avatar Handler. The manipulation leads to unrestricted upload. • https://github.com/Ramansh123454/POCs/blob/main/CSMS_RCE https://vuldb.com/?id.211049 • CWE-266: Incorrect Privilege Assignment CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2022-3548 – SourceCodester Simple Cold Storage Management System Add New Storage cross site scripting
https://notcve.org/view.php?id=CVE-2022-3548
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the component Add New Storage Handler. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. • https://github.com/Ramansh123454/POCs/blob/main/POC https://vuldb.com/?id.211048 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-707: Improper Neutralization •