Stored Cross-Site Scripting Vulnerability in Revenue Collection System by Unknown Vendor
CVE-2022-46968
5.4MEDIUM
Key Information:
- Vendor
- CVE Published:
- 27 January 2023
What is CVE-2022-46968?
The Revenue Collection System version 1.0 contains a stored cross-site scripting (XSS) vulnerability located in /index.php?page=help. This flaw allows attackers to inject malicious scripts or HTML into messages that are stored within the application, leading to potential exploitation. When unsuspecting users access these compromised messages, the injected scripts execute in their browsers, posing serious security risks and compromising user data.
