Cross-Site Scripting Vulnerability in Diary Management System by PHP Gurukul
CVE-2022-29004
Key Information:
- Vendor
- PHPgurukul
- Vendor
- CVE Published:
- 23 May 2022
Badges
Summary
The Diary Management System v1.0 contains a cross-site scripting (XSS) vulnerability that can be exploited through the Name parameter in the search-result.php file. This flaw allows an attacker to inject malicious scripts into web pages viewed by other users, potentially compromising user data and session integrity. It is crucial for developers and system administrators to sanitize user input and implement strict validation measures to mitigate this vulnerability.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
41% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability Reserved