Headline
CVE-2022-45217: CVE-2022-45217/CVE-2022-45217 at main · sudoninja-noob/CVE-2022-45217
A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Level parameter under the Add New System User module.
> [Suggested description]
> A cross-site scripting (XSS) vulnerability in Book Store Management
> System v1.0.0 allows attackers to execute arbitrary web scripts or HTML
> via a crafted payload injected into the Level parameter under the Add
> New System User module.
>
> ------------------------------------------
>
> [Vulnerability Type]
> Cross Site Scripting (XSS)
>
> ------------------------------------------
>
> [Vendor of Product]
> https://www.sourcecodester.com
>
> ------------------------------------------
>
> [Affected Product Code Base]
> Book Store Management System - V 1.0.0
>
> ------------------------------------------
>
> [Affected Component]
> Level
>
> ------------------------------------------
>
> [Attack Type]
> Local
>
> ------------------------------------------
>
> [Impact Code execution]
> true
>
> ------------------------------------------
>
> [Reference]
> https://www.sourcecodester.com/php/15748/book-store-management-system-project-using-php-codeigniter-3-free-source-code.html
>
> ------------------------------------------
>
> [Discoverer]
> Sanjay Singh