Loading HuntDB...

GHSA-45g4-83v3-gcqp

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The application fails to properly sanitize user input submitted through a form field, allowing an attacker to inject arbitrary JavaScript code. The malicious payload is stored in the backend and executed when a user or administrator accesses the affected report page. This allows attackers to exfiltrate session cookies, hijack user sessions, and perform unauthorized actions in the context of the victims browser.

Related CVEs

Key Information

GHSA ID
GHSA-45g4-83v3-gcqp
Published
September 16, 2025 3:32 PM
Last Modified
September 16, 2025 9:31 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 22, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.