PT-2021-20808 · Ice Hrm · Ice Hrm

Published

2021-06-22

·

Updated

2021-06-25

·

CVE-2021-35045

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Ice Hrm version 29.0.0.OS
Description: A cross-site scripting (XSS) issue allows attackers to execute arbitrary code via parameters to the "/app/" endpoint.
Recommendations: For Ice Hrm version 29.0.0.OS, update to a version that fixes this issue, as using vulnerable parameters in the "/app/" endpoint can lead to arbitrary code execution. As a temporary workaround, consider restricting access to the "/app/" endpoint until a patch is available. Avoid using vulnerable parameters in this endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-35045

Affected Products

Ice Hrm