CVE-2022-1816Cross-site Scripting in ZOO Management System

Severity
5.4MEDIUMNVD
CNA3.5
EPSS
0.3%
top 51.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 23
Latest updateJun 20

Description

A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issue is /zoo/admin/public_html/view_accounts?type=zookeeper of the content module. The manipulation of the argument admin_name with the input alert(1) leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-pmpw-4q9q-8w52: A vulnerability, which was classified as problematic, has been found in Zoo Management System 12022-05-24
CVEList
Zoo Management System Content Module cross site scripting2022-05-23

📋Vendor Advisories

1
Red Hat
kernel: ASoC: ops: Reject out of bounds values in snd_soc_put_xr_sx()2024-06-20
CVE-2022-1816 — Cross-site Scripting | cvebase