First published: Fri Oct 28 2022(Updated: )
Employee Record Management System v 1.2 is vulnerable to Cross Site Scripting (XSS) via editempprofile.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHPGURUKUL Employee Record Management System | =1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-37781 is medium, with a CVSS score of 5.4.
CVE-2021-37781 allows for Cross Site Scripting (XSS) attacks via the editempprofile.php page of Employee Record Management System v 1.2.
To fix the XSS vulnerability, it is recommended to apply the patches or updates provided by the PHPGURUKUL Employee Record Management System.
Yes, you can find more information about CVE-2021-37781 in the GitHub repository and the official website of PHPGURUKUL Employee Record Management System.
CWE-79 is a Common Weakness Enumeration (CWE) category that refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').