First published: Mon Sep 12 2022(Updated: )
SLiMS Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Search function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search bar.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Library Management System | =9.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38291 is a cross-site scripting (XSS) vulnerability in SLiMS Senayan Library Management System v9.4.2.
CVE-2022-38291 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search bar of SLiMS Senayan Library Management System v9.4.2.
CVE-2022-38291 has a severity rating of medium.
To fix CVE-2022-38291, it is recommended to update SLiMS Senayan Library Management System to a version that addresses the vulnerability.
More information about CVE-2022-38291 can be found at the following reference: https://github.com/slims/slims9_bulian/issues/156