First published: Thu Mar 07 2024(Updated: )
Cross Site Scripting (XSS) vulnerability in the feedback form of Online Flight Booking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the airline parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Online Flight Booking Management System | =1.0 | |
Online Flight Booking Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46091 has been classified as a medium severity vulnerability due to its potential for Cross Site Scripting (XSS) attacks.
To fix CVE-2022-46091, validate and sanitize user inputs in the feedback form to prevent script injections.
CVE-2022-46091 affects users of Online Flight Booking Management System version 1.0.
CVE-2022-46091 can be exploited through Cross Site Scripting (XSS) by injecting malicious scripts into the airline parameter.
The potential impacts of CVE-2022-46091 include unauthorized access to user sessions and data theft through malicious script execution.