PT-2021-20808 · Ice Hrm · Ice Hrm
Published
2021-06-22
·
Updated
2021-06-25
·
CVE-2021-35045
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Ice Hrm version 29.0.0.OS
Description:
A cross-site scripting (XSS) issue allows attackers to execute arbitrary code via parameters to the "/app/" endpoint.
Recommendations:
For Ice Hrm version 29.0.0.OS, update to a version that fixes this issue, as using vulnerable parameters in the "/app/" endpoint can lead to arbitrary code execution. As a temporary workaround, consider restricting access to the "/app/" endpoint until a patch is available. Avoid using vulnerable parameters in this endpoint to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ice Hrm