Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Self-XSS.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://news.websoft.ru/_wt/wiki_base/7175852133775323458 |
|
History
Tue, 22 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published: 2022-12-12T00:00:00.000Z
Updated: 2025-04-22T18:11:59.495Z
Reserved: 2022-12-09T00:00:00.000Z
Link: CVE-2022-46904
Updated: 2024-08-03T14:47:27.652Z
Status : Modified
Published: 2022-12-12T21:15:10.493
Modified: 2025-04-22T19:15:51.387
Link: CVE-2022-46904
No data.
ReportizFlow