VulnerabilityModified
CVE-2022-36254
Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple parameters such as "fullname".
MEDIUM 5.4EPSS 0.74%
Does this matter?
Lower severity and a low EPSS score (0.74%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple parameters such as "fullname".
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.74% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- hotel management system project/hotel management system
- Source
- cve@mitre.org
References
- https://gist.github.com/ziyishen97/c464b459df73c4cef241e7ec774b7cf6Exploit, Third Party Advisory
- https://github.com/tramyardg/hotel-mgmt-systemProduct, Third Party Advisory
- https://gist.github.com/ziyishen97/c464b459df73c4cef241e7ec774b7cf6Exploit, Third Party Advisory
- https://github.com/tramyardg/hotel-mgmt-systemProduct, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.