Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Stored XSS.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-49683 | Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Stored XSS. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://news.websoft.ru/_wt/wiki_base/7175851369410989446 |
|
History
Tue, 22 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-22T18:41:47.445Z
Reserved: 2022-12-09T00:00:00.000Z
Link: CVE-2022-46903
Updated: 2024-08-03T14:47:27.602Z
Status : Modified
Published: 2022-12-12T21:15:10.433
Modified: 2025-04-22T19:15:51.200
Link: CVE-2022-46903
No data.
OpenCVE Enrichment
No data.
EUVD