A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the flexiportal/GeneralInfo.aspx strAction parameter.
References
Configurations
Information
Published : 2018-09-06 16:29
Updated : 2019-11-12 10:15
NVD link : CVE-2018-12234
Mitre link : CVE-2018-12234
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
myadrenalin
- adrenalin