SourceCodester Simple Cold Storage Management System Create User cross site scripting
CVE-2022-3546
2.4LOW
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 17 October 2022
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2022-3546?
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /csms/admin/?page=user/list of the component Create User Handler. The manipulation of the argument First Name/Last Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-211046 is the identifier assigned to this vulnerability.
Affected Version(s)
Simple Cold Storage Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.