CVE-2022-4091

LOW

SourceCodester Canteen Management System - XSS

Title source: llm
STIX 2.1

Description

A vulnerability was found in SourceCodester Canteen Management System. It has been classified as problematic. This affects the function query of the file food.php. The manipulation of the argument product_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214359.

Scores

CVSS v3 3.5
EPSS 0.0021
EPSS Percentile 43.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-707
Status published
Products (1)
canteen_management_system_project/canteen_management_system
Published Nov 25, 2022
Tracked Since Feb 18, 2026