← Back

CVE-2022-45008

nvd nist
Published: Dec 7, 2022Modified: Apr 23, 2025

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: NVD

Description

Online Leave Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /leave_system/admin/?page=maintenance/department. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted payload injected into the Name field under the Create New module.

Affected (1)

Online Leave Management System
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.0

Timeline

No history available yet.