leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.", "datePublished": "2022-05-23T11:30:14Z", "dateModified": "2024-10-15T17:13:17Z", "keywords": "CVE-2022-1816, vulnerability, CVE, security, Zoo Management System, unspecified", "about": { "@type": "SoftwareApplication", "name": "Zoo Management System", "applicationCategory": "SecurityApplication", "operatingSystem": "All" } }
CVE-2022-1816 LOW

CVE-2022-1816: Zoo Management System Content Module cross site scripting

Vendor Unspecified
Product Zoo Management System
Weakness CWE-79 · XSS
Published May 23, 2022
Last update October 15, 2024

CVSS base score

3.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issue is /zoo/admin/public_html/view_accounts?type=zookeeper of the content module. The manipulation of the argument admin_name with the input <script>alert(1)</script> leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.

Key dates

02Disclosure timeline

May 23, 2022 CVE published
October 15, 2024 Record updated