Filtered by vendor Minthcm Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-25839 1 Minthcm 1 Minthcm 2024-08-03 9.8 Critical
A weak password requirement vulnerability exists in the Create New User function of MintHCM RELEASE 3.0.8, which could lead an attacker to easier password brute-forcing.
CVE-2021-25838 1 Minthcm 1 Minthcm 2024-08-03 6.1 Medium
The Import function in MintHCM RELEASE 3.0.8 allows an attacker to execute a cross-site scripting (XSS) payload in file-upload.
CVE-2024-36656 1 Minthcm 1 Minthcm 2024-08-02 6.1 Medium
In MintHCM 4.0.3, a registered user can execute arbitrary JavaScript code and achieve a reflected Cross-site Scripting (XSS) attack.