First published: Fri Mar 27 2020(Updated: )
Sunnet eHRD, a human training and development management system, contains vulnerability of Cross-Site Scripting (XSS), attackers can inject arbitrary command into the system and launch XSS attack.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Ehrd | =8.0 | |
Sun Ehrd | =9.0 |
Update to version 10 or latest, or contact Sunnet for fixing patch.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10509 is classified as a moderate severity vulnerability due to its potential for Cross-Site Scripting attacks.
To fix CVE-2020-10509, ensure that you are using the latest patched version of Sunnet eHRD, which includes security improvements to prevent XSS attacks.
CVE-2020-10509 affects Sunnet eHRD versions 8.0 and 9.0.
CVE-2020-10509 is associated with Cross-Site Scripting (XSS) attacks that allow attackers to inject arbitrary commands.
Attackers can exploit CVE-2020-10509 by injecting malicious scripts via user inputs that the application fails to properly sanitize.