CVE-2022-29004: XSS
Published May 23, 2022
·Updated
Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.
Affected Software
2 affected components
E-diary Management System Project E-diary Management System=1.0
Phpgurukul e-Diary Management System=1.0
Event History
May 23, 2022
CVE Published
via MITRE·03:38 PM
Data Sourced
via MITRE·03:38 PM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-29004?
CVE-2022-29004 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2022-29004?
To fix CVE-2022-29004, sanitize and validate user input in the Name parameter in search-result.php to prevent XSS attacks.
3
Which versions are affected by CVE-2022-29004?
CVE-2022-29004 affects version 1.0 of the Diary Management System software.
4
What type of vulnerability is CVE-2022-29004?
CVE-2022-29004 is a cross-site scripting (XSS) vulnerability.
5
Where does CVE-2022-29004 occur in the application?
CVE-2022-29004 occurs in the search-result.php file of the Diary Management System.