CVE-2022-1817 LOW

CVE-2022-1817: Badminton Center Management System Userlist Module cross site scripting

Vendor Unspecified
Product Badminton Center Management System
Weakness CWE-79 · XSS
Published May 23, 2022
Last update April 15, 2025

CVSS base score

3.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the userlist module at /bcms/admin/?page=user/list. The manipulation of the argument username with the input </td><img src="" onerror="alert(1)"><td>1 leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.

Key dates

02Disclosure timeline

May 23, 2022 CVE published
April 15, 2025 Record updated