vendor:
Core HCM
by:
Rishu Ranjan
6.1
CVSS
MEDIUM
Reflected Cross Site Scripting (XSS)
79
CWE
Product Name: Core HCM
Affected Version From: 5.4.0
Affected Version To: 5.4.0
Patch Exists: YES
Related CWE: CVE-2018-12653
CPE: a:myadrenalin:core_hcm:5.4.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Multiple
2018
Adrenalin Core HCM 5.4.0 – ‘ReportID’ Reflected Cross-Site Scripting
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin Core HCM v5.4.0 HRMS Software. The user supplied input containing malicious JavaScript is echoed back as it is in JavaScript code in an HTML response.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.