VulnerabilityModified
CVE-2022-36668
Garage Management System 1.0 is vulnerable to Stored Cross Site Scripting (XSS) on several parameters.
MEDIUM 5.4EPSS 0.61%
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
Garage Management System 1.0 is vulnerable to Stored Cross Site Scripting (XSS) on several parameters. The vulnerabilities exist during creating or editing the parts under parameters. Using the XSS payload, the Stored XSS triggered and can be used for further attack vector.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- garage management system project/garage management system
- Source
- cve@mitre.org
References
- https://github.com/saitamang/POC-DUMP/blob/main/Garage%20Management%20System/README.mdExploit, Third Party Advisory
- https://www.sourcecodester.com/php/15485/garage-management-system-using-phpmysql-source-code.htmlThird Party Advisory
- https://github.com/saitamang/POC-DUMP/blob/main/Garage%20Management%20System/README.mdExploit, Third Party Advisory
- https://www.sourcecodester.com/php/15485/garage-management-system-using-phpmysql-source-code.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.