CVE-2004-2435: XSS
Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" using HTML Access, allows remote attackers to inject arbitrary web script or HTML via unspecified (1) debugging or (2) utility scripts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2435?
The severity of CVE-2004-2435 is considered to be moderate due to the ability to execute arbitrary web scripts via XSS.
How do I fix CVE-2004-2435?
To fix CVE-2004-2435, ensure that your PeopleSoft HRMS version is updated to a patched release that addresses this vulnerability.
Who is affected by CVE-2004-2435?
Organizations using PeopleSoft HRMS version 7.0 with web-enabled configurations are affected by CVE-2004-2435.
What type of attack does CVE-2004-2435 enable?
CVE-2004-2435 enables remote attackers to perform cross-site scripting (XSS) attacks.
What are the consequences of CVE-2004-2435?
The consequences of CVE-2004-2435 include potential information leakage and unauthorized actions performed in the context of the user's session.