MEDIUM · 5.4

CVE-2022-30494

In oretnom23 Automotive Shop Management System v1.0, the first and last name user fields suffer from a stored XSS Injection Vulnerability allowing remote attackers to gain admin access and view intern...

Vulnerability Description

In oretnom23 Automotive Shop Management System v1.0, the first and last name user fields suffer from a stored XSS Injection Vulnerability allowing remote attackers to gain admin access and view internal IPs.

CVSS Score

5.4

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
Automotive Shop Management System ProjectAutomotive Shop Management System1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-30494?

CVE-2022-30494 is a vulnerability with a CVSS score of 5.4 (MEDIUM). In oretnom23 Automotive Shop Management System v1.0, the first and last name user fields suffer from a stored XSS Injection Vulnerability allowing remote attackers to gain admin access and view intern...

How severe is CVE-2022-30494?

CVE-2022-30494 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-30494?

Check the references section above for vendor advisories and patch information. Affected products include: Automotive Shop Management System Project Automotive Shop Management System.