First published: Tue Jul 12 2022(Updated: )
A vulnerability classified as problematic has been found in SourceCodester Hotel Management System 2.0. Affected is an unknown function of the file /ci_hms/massage_room/edit/1 of the component Room Edit Page. The manipulation of the argument massageroomDetails with the input "><script>alert("XSS")</script> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hotel Management System Project Hotel Management System | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-2292 is medium (5.4).
The affected software of CVE-2022-2292 is SourceCodester Hotel Management System 2.0.
The CWE ID of CVE-2022-2292 is CWE-79.
We do not provide information on exploiting vulnerabilities.
An official fix or patch has not been released at the moment. It is recommended to contact the vendor or project team for updates or mitigation steps.