CVE-2022-38291: XSS
SLiMS Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Search function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search bar.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-38291?
CVE-2022-38291 is a cross-site scripting (XSS) vulnerability in SLiMS Senayan Library Management System v9.4.2.
How does CVE-2022-38291 affect SLiMS Senayan Library Management System?
CVE-2022-38291 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search bar of SLiMS Senayan Library Management System v9.4.2.
What is the severity of CVE-2022-38291?
CVE-2022-38291 has a severity rating of medium.
How can I fix CVE-2022-38291 in SLiMS Senayan Library Management System?
To fix CVE-2022-38291, it is recommended to update SLiMS Senayan Library Management System to a version that addresses the vulnerability.
Where can I find more information about CVE-2022-38291?
More information about CVE-2022-38291 can be found at the following reference: https://github.com/slims/slims9_bulian/issues/156