CVE-2022-3546
published 2022-10-17CVE-2022-3546: A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0 and classified as problematic. Affected by this issue is some unknown…
PriorityP422medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
0.52%
40.4th percentile
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /csms/admin/?page=user/list of the component Create User Handler. The manipulation of the argument First Name/Last Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-211046 is the identifier assigned to this vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oretnom23 | simple_cold_storage_management_system | — | — |
| sourcecodester | simple_cold_storage_management_system | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SourceCodester Simple Cold Storage Management System 1.0 Create User list First Name/Last Name cross site scripting (EUVD-2022-42912)
vuldb·2026-07-17·CVSS 4.8
CVE-2022-3546 [MEDIUM] SourceCodester Simple Cold Storage Management System 1.0 Create User list First Name/Last Name cross site scripting (EUVD-2022-42912)
A vulnerability identified as problematic has been detected in SourceCodester Simple Cold Storage Management System 1.0. Affected is an unknown function of the file /csms/admin/?page=user/list of the component Create User Handler. This manipulation of the argument First Name/Last Name causes cross site scripting.
This vulnerability is registered as CVE-2022-3546. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
GHSA
GHSA-c492-9w3p-xq6q: A vulnerability was found in SourceCodester Simple Cold Storage Management System 1
ghsa_unreviewed·2022-10-17
CVE-2022-3546 [MEDIUM] CWE-707 GHSA-c492-9w3p-xq6q: A vulnerability was found in SourceCodester Simple Cold Storage Management System 1
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /csms/admin/?page=user/list of the component Create User Handler. The manipulation of the argument First Name/Last Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-211046 is the identifier assigned to this vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-17
Published