Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an unauthenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Reflected XSS.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-49685 | Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an unauthenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Reflected XSS. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://news.websoft.ru/_wt/wiki_base/7175852393019676262 |
|
History
Tue, 22 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-22T18:06:08.332Z
Reserved: 2022-12-09T00:00:00.000Z
Link: CVE-2022-46905
Updated: 2024-08-03T14:47:27.730Z
Status : Modified
Published: 2022-12-12T21:15:10.543
Modified: 2025-04-22T18:15:57.613
Link: CVE-2022-46905
No data.
OpenCVE Enrichment
No data.
EUVD