Record summary

CVE-2022-41358 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 8, 2025 · Source: CVE List

Proofs of concept

2

Catalogued exploits

ExploitDBGarage Management System 1.0 (categoriesName) - Stored XSSExploitDB exploitby ub3rsickNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubthecasual/CVE-2022-41358Repository PoCby thecasualStars: 0Not analyzed6 files

185.2 KiB

GitHub

PoC details

References

7