CVE-2021-38583
13.08.2021, 14:15
openBaraza HCM 3.1.6 does not properly neutralize user-controllable input, which allows reflected cross-site scripting (XSS) on multiple pages: hr/subscription.jsp and hr/application.jsp and and hr/index.jsp (with view= and data=).
Vendor | Product | Version |
---|---|---|
openbaraza | openbaraza_human_capital_management | 3.1.6 |
𝑥
= Vulnerable software versions