Stored Cross-Site Scripting Vulnerability in Revenue Collection System by Unknown Vendor
CVE-2022-46968

5.4MEDIUM

What is CVE-2022-46968?

The Revenue Collection System version 1.0 contains a stored cross-site scripting (XSS) vulnerability located in /index.php?page=help. This flaw allows attackers to inject malicious scripts or HTML into messages that are stored within the application, leading to potential exploitation. When unsuspecting users access these compromised messages, the injected scripts execute in their browsers, posing serious security risks and compromising user data.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.