First published: Fri Jul 29 2022(Updated: )
A vulnerability, which was classified as problematic, was found in SourceCodester Garage Management System 1.0. Affected is an unknown function of the file /php_action/createUser.php. The manipulation of the argument userName with the input lala<img src="" onerror=alert(1)> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Garage Management System Project Garage Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-2579 is medium, with a severity value of 5.4.
CVE-2022-2579 affects SourceCodester Garage Management System 1.0 through an unknown function in the file /php_action/createUser.php.
CVE-2022-2579 is a cross-site scripting vulnerability (XSS) found in SourceCodester Garage Management System 1.0.
The argument 'userName' can be manipulated in CVE-2022-2579 by injecting malicious code such as <img src='' onerror=alert(1)>.
At the moment, there is no information available about a fix for CVE-2022-2579. It is recommended to follow the references provided for any updates or patches.