CVE-2022-30003

Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then create new products containing XSS payloads in the 'Product Title' and 'Short Description' fields.
Configurations

Configuration 1 (hide)

cpe:2.3:a:online_market_place_site_project:online_market_place_site:1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:02

Type Values Removed Values Added
References () https://packetstormsecurity.com/files/168250/omps10-xss.txt - Exploit, Third Party Advisory, VDB Entry () https://packetstormsecurity.com/files/168250/omps10-xss.txt - Exploit, Third Party Advisory, VDB Entry
References () https://www.sourcecodester.com/php/15273/online-market-place-site-phpoop-free-source-code.html - Product () https://www.sourcecodester.com/php/15273/online-market-place-site-phpoop-free-source-code.html - Product

Information

Published : 2022-09-26 19:15

Updated : 2024-11-21 07:02


NVD link : CVE-2022-30003

Mitre link : CVE-2022-30003

CVE.ORG link : CVE-2022-30003


JSON object : View

Products Affected

online_market_place_site_project

  • online_market_place_site
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')