Vulnerability Description
Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple parameters such as "fullname".
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hotel Management System Project | Hotel Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://gist.github.com/ziyishen97/c464b459df73c4cef241e7ec774b7cf6ExploitThird Party Advisory
- https://github.com/tramyardg/hotel-mgmt-systemProductThird Party Advisory
- https://gist.github.com/ziyishen97/c464b459df73c4cef241e7ec774b7cf6ExploitThird Party Advisory
- https://github.com/tramyardg/hotel-mgmt-systemProductThird Party Advisory
FAQ
What is CVE-2022-36254?
CVE-2022-36254 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple paramete...
How severe is CVE-2022-36254?
CVE-2022-36254 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-36254?
Check the references section above for vendor advisories and patch information. Affected products include: Hotel Management System Project Hotel Management System.