CVE-2022-33075

MEDIUM

Zoo Management System v1.0 - XSS

Title source: llm
STIX 2.1

Description

A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via unspecified vectors.

Exploits (1)

nomisec WORKING POC
by angelopioamirante · poc
https://github.com/angelopioamirante/CVE-2022-33075

References (3)

Core 3
Core References
Product x_refsource_misc
http://sourcecodester.com
Not Applicable x_refsource_misc
http://zoo.com

Scores

CVSS v3 5.4
EPSS 0.0019
EPSS Percentile 40.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
phpgurukul/zoo_management_system 1.0
Published Jul 05, 2022
Tracked Since Feb 18, 2026