CVE-2022-2800
published 2022-08-12CVE-2022-2800: A vulnerability, which was classified as problematic, has been found in SourceCodester Gym Management System. Affected by this issue is some unknown…
PriorityP429medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.49%
38.8th percentile
A vulnerability, which was classified as problematic, has been found in SourceCodester Gym Management System. Affected by this issue is some unknown functionality. The manipulation leads to clickjacking. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-206246 is the identifier assigned to this vulnerability.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sourcecodester | gym_management_system | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Nuclei
Yahoo User Interface library (YUI2) TreeView v2.8.2 - Cross-Site Scripting
nuclei·CVSS 6.1
CVE-2022-48197 [MEDIUM] Yahoo User Interface library (YUI2) TreeView v2.8.2 - Cross-Site Scripting
Yahoo User Interface library (YUI2) TreeView v2.8.2 - Cross-Site Scripting
Reflected cross-site scripting (XSS) exists in the TreeView of YUI2 through 2800: up.php sam.php renderhidden.php removechildren.php removeall.php readd.php overflow.php newnode2.php newnode.php.
Template:
id: CVE-2022-48197
info:
name: Yahoo User Interface library (YUI2) TreeView v2.8.2 - Cross-Site Scripting
author: ctflearner
severity: medium
description: |
Reflected cross-site scripting (XSS) exists in the TreeView of YUI2 through 2800: up.php sam.php renderhidden.php removechildren.php removeall.php readd.php overflow.php newnode2.php newnode.php.
impact: |
Attackers can inject malicious JavaScript through crafted mode parameters in multiple TreeView PHP files, potentially stealing user session tokens and p
No writeups or analysis indexed.
https://github.com/Blythe-LU/Record4/blob/main/Gym%20management%20system%20project%20-%20ClickJacking%20exists%20on%20multiple%20pages.mdhttps://vuldb.com/?id.206246https://github.com/Blythe-LU/Record4/blob/main/Gym%20management%20system%20project%20-%20ClickJacking%20exists%20on%20multiple%20pages.mdhttps://vuldb.com/?id.206246
2022-08-12
Published