Description
IceHrm 23.0.0.OS does not sufficiently encode user-controlled input, which creates a Cross-Site Scripting (XSS) vulnerability via /icehrm/app/fileupload_page.php, in multiple parameters. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload and partially hijacking the victim's browser.
No analysis available yet.
Remediation
Vendor Solution
There is no reported solution at this time.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58526 | IceHrm 23.0.0.OS does not sufficiently encode user-controlled input, which creates a Cross-Site Scripting (XSS) vulnerability via /icehrm/app/fileupload_page.php, in multiple parameters. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload and partially hijacking the victim's browser. |
References
History
Fri, 18 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-10-18T15:23:29.039Z
Reserved: 2023-11-24T12:40:05.406Z
Link: CVE-2023-6282
Updated: 2024-08-02T08:28:21.329Z
Status : Modified
Published: 2024-01-25T12:15:45.917
Modified: 2024-11-21T08:43:31.863
Link: CVE-2023-6282
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD