CVE-2022-24582

Accounting Journal Management 1.0 is vulnerable to XSS-PHPSESSID-Hijacking. The parameter manage_user from User lists is vulnerable to XSS-Stored and PHPSESSID attacks. The malicious user can attack the system by using the already session which he has from inside and outside of the network.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:accounting_journal_management_project:accounting_journal_management:1.0:*:*:*:*:*:*:*

Information

Published : 2022-02-24 07:15

Updated : 2022-03-02 10:17


NVD link : CVE-2022-24582

Mitre link : CVE-2022-24582


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

accounting_journal_management_project

  • accounting_journal_management