Accounting Journal Management 1.0 is vulnerable to XSS-PHPSESSID-Hijacking. The parameter manage_user from User lists is vulnerable to XSS-Stored and PHPSESSID attacks. The malicious user can attack the system by using the already session which he has from inside and outside of the network.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-02-22T11:12:45

Updated: 2022-02-22T11:12:45

Reserved: 2022-02-07T00:00:00


Link: CVE-2022-24582

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-02-24T15:15:29.593

Modified: 2022-03-02T18:17:48.967


Link: CVE-2022-24582

JSON object: View

cve-icon Redhat Information

No data.

CWE