CVE Published: 22/09/2022 |
CVE Updated: 16/09/2024 |
CVE Year: 2022 Source: TR-CERT |
Vendor: Yordam Bilgi Teknolojileri |
Product: Yordam Bilgi Teknolojileri Status : PUBLISHED
CVE-2022-2266 Description
University Library Automation System developed by Yordam Bilgi Teknolojileri before version 19.2 has an unauthenticated Reflected XSS vulnerability. This has been fixed in the version 19.2
Metrics
CVSS Version: 3.1 |
Base Score: 6.1 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-ID: CWE-79 CWE Name: CWE-79 Improper Neutralization of Input During Web Page Generation (
Cross-site Scripting
) Source: Yordam Bilgi Teknolojileri
Common Attack Pattern Enumeration and Classification (CAPEC)