CVE-2022-2020: SourceCodester Prison Management System System Name cross site scripting
A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/?page=systeminfo of the component System Name Handler. The manipulation with the input <img src="" onerror="alert(1)"> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2020?
The severity of CVE-2022-2020 is medium.
What is the affected software for CVE-2022-2020?
The affected software for CVE-2022-2020 is SourceCodester Prison Management System 1.0.
What is the CWE category for CVE-2022-2020?
The CWE category for CVE-2022-2020 is CWE-79 (Cross-Site Scripting).
How can I fix CVE-2022-2020?
To fix CVE-2022-2020, it is recommended to update to a patched version or apply the necessary security patches.
Where can I find more information about CVE-2022-2020?
More information about CVE-2022-2020 can be found at the following references: [Reference 1](https://github.com/ch0ing/vul/blob/main/WebRay.com.cn/Prison%20Management%20System(XSS).md), [Reference 2](https://vuldb.com/?id.201368).