CVE-2022-45217: XSS
Published Dec 7, 2022
·Updated
A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Level parameter under the Add New System User module.
Affected Software
1 affected component
Book Store Management System Project Book Store Management System=1.0.0
Event History
Dec 7, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-45217?
CVE-2022-45217 has a moderate severity level due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2022-45217?
To fix CVE-2022-45217, validate and sanitize user input in the Level parameter of the Add New System User module.
3
Who is affected by CVE-2022-45217?
CVE-2022-45217 affects users of Book Store Management System version 1.0.0.
4
What is the impact of CVE-2022-45217?
The impact of CVE-2022-45217 allows attackers to execute arbitrary scripts or HTML, potentially compromising user data.
5
Is there a patch available for CVE-2022-45217?
As of now, there is no official patch available for CVE-2022-45217, thus manual remediation is required.