Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4pw7-599v-2mmh

Опубликовано: 12 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Self-XSS.

Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Self-XSS.

EPSS

Процентиль: 70%
0.00629
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 3 лет назад

Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Self-XSS.

EPSS

Процентиль: 70%
0.00629
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79