CVE-2023-45540: Medium severity Jorani Leave Management System vulnerability
An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the comment field of the List of Leave requests page.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue in Jorani Leave Management System?
The vulnerability ID for this issue in Jorani Leave Management System is CVE-2023-45540.
What is the severity level of CVE-2023-45540?
CVE-2023-45540 has a severity level of 6.5 (medium).
How does this vulnerability in Jorani Leave Management System allow an attacker to execute arbitrary HTML code?
This vulnerability in Jorani Leave Management System allows a remote attacker to execute arbitrary HTML code by submitting a crafted script to the comment field of the List of Leave requests page.
Which version of Jorani Leave Management System is affected by CVE-2023-45540?
Jorani Leave Management System version 1.0.3 is affected by CVE-2023-45540.
Is there a proof of concept (PoC) available for CVE-2023-45540?
Yes, a proof of concept (PoC) is available for CVE-2023-45540. You can find it at the following link: [GitHub - HTML-Injection PoC](https://github.com/soundarkutty/HTML-Injection/blob/main/POC.md)