Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3gqx-89wv-8h66

Опубликовано: 12 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Reflected XSS.

Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Reflected XSS.

EPSS

Процентиль: 70%
0.00629
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 3 лет назад

Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Reflected XSS.

EPSS

Процентиль: 70%
0.00629
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79