All details about CVE-2022-43097
Software: Phpgurukul User Registration & User Management System v3.0
Software Link: https://phpgurukul.com/user-registration-login-and-user-management-system-with-admin-panel/
Description: Phpgurukul User Registration & User Management System v3.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the first name and last name parameters of the registration form & login pages.
Vulnerability Type: Stored Cross Site Scripting (XSS)
Affected Product Code Base: User Registration & Login and User Management System With admin panel
Affected Component: http://127.0.0.1/login.php, http://127.0.0.1/welcome.php
Attack Type: Remote
Attack Vectors: Malicious payload get saved on to the webserver as first name and last name.