Stored Cross-Site Scripting Vulnerabilities in Phpgurukul User Registration System
CVE-2022-43097
5.4MEDIUM
Key Information:
- Vendor
- CVE Published:
- 5 December 2022
Badges
๐พ Exploit Exists
What is CVE-2022-43097?
The Phpgurukul User Registration & User Management System v3.0 has been found to contain multiple vulnerabilities that allow for stored cross-site scripting (XSS) attacks. These vulnerabilities can be exploited through the firstname and lastname parameters of the registration and login forms. Malicious actors can inject scripts that may lead to unauthorized data access and compromised user accounts, making user management and registration processes exceptionally risky for administrators and users alike.
