First published: Mon Sep 12 2022(Updated: )
Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple parameters such as "fullname".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hotel Management System Project Hotel Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36254 is a vulnerability in the tramyardg Hotel Management System 1.0 that allows remote attackers to inject arbitrary web script or HTML through multiple parameters.
CVE-2022-36254 has a severity value of 5.4, which is considered medium.
The affected software of CVE-2022-36254 is the tramyardg Hotel Management System 1.0.
Remote attackers can exploit CVE-2022-36254 by injecting arbitrary web script or HTML through multiple parameters of the tramyardg Hotel Management System 1.0, such as "fullname".
To fix CVE-2022-36254, it is recommended to update the tramyardg Hotel Management System to a patched version that addresses the cross-site scripting vulnerabilities.