CVE-2022-4234

LOW

Canteen Management System - Cross-Site Scripting in youthappam/brand.php via brand_name Argument

Title source: llm
STIX 2.1

Description

A vulnerability was found in SourceCodester Canteen Management System. It has been rated as problematic. This issue affects the function builtin_echo of the file youthappam/brand.php. The manipulation of the argument brand_name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214595.

References (2)

Core 2
Core References
Third Party Advisory
https://vuldb.com/?id.214595

Scores

CVSS v3 3.5
EPSS 0.0041
EPSS Percentile 32.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-707
Status published
Products (1)
canteen_management_system_project/canteen_management_system
Published Nov 30, 2022
Tracked Since Feb 18, 2026