CVE-2022-4252

LOW

Canteen Management System - Cross-Site Scripting in categories.php builtin_echo Function

Title source: llm
STIX 2.1

Description

A vulnerability was found in SourceCodester Canteen Management System. It has been classified as problematic. This affects the function builtin_echo of the file categories.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214629 was assigned to this vulnerability.

References (2)

Core 2
Core References
Third Party Advisory
https://vuldb.com/?id.214629

Scores

CVSS v3 3.5
EPSS 0.0041
EPSS Percentile 32.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-707
Status published
Products (1)
canteen_management_system_project/canteen_management_system
Published Dec 01, 2022
Tracked Since Feb 18, 2026