CVE-2019-11032

In EasyToRecruit (E2R) before 2.11, the upload feature and the Candidate Profile Management feature are prone to Cross Site Scripting (XSS) injection in multiple locations.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:hr-technologies:easytorecruit:*:*:*:*:*:*:*:*

Information

Published : 2019-04-24 08:29

Updated : 2019-10-09 16:45


NVD link : CVE-2019-11032

Mitre link : CVE-2019-11032


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

hr-technologies

  • easytorecruit