First published: Fri Oct 14 2022(Updated: )
A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been classified as problematic. Affected is an unknown function of the component Master List. The manipulation of the argument city/state/country/position leads to cross site scripting. It is possible to launch the attack remotely. VDB-210786 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Human Resource Management System Project Human Resource Management System | =1.0 | |
Oretnom23 Human Resource Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2022-3497.
The severity of CVE-2022-3497 is medium with a CVSS score of 5.4.
The affected software of CVE-2022-3497 is SourceCodester Human Resource Management System 1.0.
The CWE classification of CVE-2022-3497 includes CWE-79 (Cross-Site Scripting), CWE-707 (Improper Enforcement of Message Integrity During Transmission), and CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component).
To fix CVE-2022-3497, it is recommended to apply the latest security patches or updates provided by the vendor.