Accounting Journal Management 1.0 is vulnerable to XSS-PHPSESSID-Hijacking. The parameter manage_user from User lists is vulnerable to XSS-Stored and PHPSESSID attacks. The malicious user can attack the system by using the already session which he has from inside and outside of the network.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T04:13:56.626Z

Reserved: 2022-02-07T00:00:00

Link: CVE-2022-24582

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-02-24T15:15:29.593

Modified: 2024-11-21T06:50:41.753

Link: CVE-2022-24582

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.