The job posting recommendation form in Persis Human Resource Management Portal (Versions 17.2.00 through 17.2.35 and 19.0.00 through 19.0.20), when the "Recommend job posting" function is enabled, allows XSS via the SENDER parameter.
References
Link | Resource |
---|---|
https://it-sec.de/ger/Aktuelles-Termine/it.sec-blog/it.sec-Research-Team-findet-unbekannte-Schwachstelle-in-Persis-Online-Bewerberportal | Exploit Third Party Advisory |
https://slashcrypto.org/2021/02/20/CVE-2020-35753/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2021-01-26 10:15
Updated : 2022-10-06 19:24
NVD link : CVE-2020-35753
Mitre link : CVE-2020-35753
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
linux
- linux_kernel
microsoft
- windows
persis
- human_resource_management_portal