PT-2022-22018 · Benjamin Balet · Jorani

Published

2022-06-27

·

Updated

2023-10-25

·

CVE-2022-34133

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Benjamin BALET Jorani version 1.0
Description The issue is related to a cross-site scripting (XSS) vulnerability. This vulnerability can be exploited via the Comment parameter at the application/controllers/Leaves.php endpoint.
Recommendations For Benjamin BALET Jorani version 1.0, as a temporary workaround, consider restricting access to the Comment parameter in the application/controllers/Leaves.php endpoint until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-34133

Affected Products

Jorani