Wedding Hall Booking System是Carlo Montero个人开发者的一个简单的 PHP 标题婚礼大厅预订系统。 SourceCodester Wedding Hall Booking System存在跨站脚本漏洞,该漏洞源于其 /whbs/admin/?page=user组件中Staff User Profile代码的未知部分对参数First Name/Last Name的操作会导致跨站脚本。该攻击方法已经被公开并且可以由远程发起,存在被利用的风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Wedding Hall Booking System | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-2694 | 6.3 MEDIUM | SourceCodester Company Website CMS unrestricted upload |
| CVE-2022-2693 | 6.3 MEDIUM | SourceCodester Electronic Medical Records System UPDATE Statement register.php sql injecti |
| CVE-2022-2688 | 6.3 MEDIUM | SourceCodester Expense Management System POST Parameter report.php fetch_report_credit sql |
| CVE-2022-2687 | 6.3 MEDIUM | SourceCodester Gym Management System sql injection |
| CVE-2022-2691 | 3.5 LOW | SourceCodester Wedding Hall Booking System Profile Page cross site scripting |
| CVE-2022-2690 | 3.5 LOW | SourceCodester Wedding Hall Booking System Booking Form cross site scripting |
| CVE-2022-2689 | 3.5 LOW | SourceCodester Wedding Hall Booking System Contact Page cross site scripting |
No comments yet