PT-2022-17046 · Ice Hrm · Ice Hrm

Cooliscool

·

Published

2022-02-28

·

Updated

2022-03-09

·

CVE-2022-25013

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ice Hrm version 30.0.0.OS
Description The issue is related to multiple reflected cross-site scripting (XSS) vulnerabilities. These vulnerabilities are exploited via the key and fm parameters in the component login.php.
Recommendations For Ice Hrm version 30.0.0.OS, avoid using the key and fm parameters in the login.php component until a fix is available. As a temporary workaround, consider restricting access to the login.php component to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25013

Affected Products

Ice Hrm