Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ESP HR Management allows Stored XSS attack. An attacker might inject a script to be run in user's browser. After multiple attempts to contact the vendor we did not receive any answer. The finder provided the information that this issue affects ESP HR Management versions before 6.6.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Sep 2024 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Wed, 28 Aug 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Connx
Connx esp Hr Management |
|
CPEs | cpe:2.3:a:connx:esp_hr_management:*:*:*:*:*:*:*:* | |
Vendors & Products |
Connx
Connx esp Hr Management |
|
Metrics |
ssvc
|
Wed, 28 Aug 2024 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ESP HR Management allows Stored XSS attack. An attacker might inject a script to be run in user's browser. After multiple attempts to contact the vendor we did not receive any answer. The finder provided the information that this issue affects ESP HR Management versions before 6.6. | |
Title | Stored XSS in ConnX ESP HR Management | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: CERT-PL
Published: 2024-08-28T10:29:48.889Z
Updated: 2024-08-28T13:22:27.559Z
Reserved: 2024-07-30T09:51:38.818Z
Link: CVE-2024-7269

Updated: 2024-08-28T13:22:20.644Z

Status : Analyzed
Published: 2024-08-28T11:15:13.850
Modified: 2024-09-19T14:37:26.380
Link: CVE-2024-7269

No data.