vendor:
Jorani
by:
Javier Olmedo
5.4
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: Jorani
Affected Version From: 0.6.5
Affected Version To: 0.6.5
Patch Exists: NO
Related CWE: CVE-2018-15917
CPE: a:bbalet:jorani:0.6.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows, Linux
2018
Jorani Leave Management System 0.6.5 – Cross-Site Scripting
Language parameter is vulnerable to Persistent Cross-Site Scripting (XSS) attacks through a GET request in which the values are stored in the user session.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.