PT-2022-27363 · Unknown · Online Leave Management System
Realguoxiufeng
·
Published
2022-12-07
·
Updated
2025-04-23
·
CVE-2022-45008
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Online Leave Management System version 1.0
Description
The issue is related to a stored cross-site scripting (XSS) vulnerability. This vulnerability is located in the
/leave system/admin/?page=maintenance/department component and allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Create New module.Recommendations
For Online Leave Management System version 1.0, as a temporary workaround, consider restricting access to the
/leave system/admin/?page=maintenance/department component to minimize the risk of exploitation. Avoid using the Name field in the Create New module until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Online Leave Management System