CVE-2022-2020
SourceCodester Prison Management System System Name cross site scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/?page=system_info of the component System Name Handler. The manipulation with the input <img src="" onerror="alert(1)"> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Se ha encontrado una vulnerabilidad, clasificada como problemática, en SourceCodester Prison Management System versión 1.0. Este problema afecta a una funcionalidad desconocida del archivo /admin/?page=system_info del componente System Name Handler. La manipulación con la entrada (img src="" onerror="alert(1)") conlleva a un ataque de tipo cross site scripting. El ataque puede ser lanzado remotamente. La explotación ha sido revelada al público y puede ser usada
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-06-07 CVE Reserved
- 2022-06-07 CVE Published
- 2023-12-29 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/ch0ing/vul/blob/main/WebRay.com.cn/Prison%20Management%20System%28XSS%29.md | X_refsource_misc | |
https://vuldb.com/?id.201368 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Prison Management System Project Search vendor "Prison Management System Project" | Prison Management System Search vendor "Prison Management System Project" for product "Prison Management System" | 1.0 Search vendor "Prison Management System Project" for product "Prison Management System" and version "1.0" | - |
Affected
|