← Back

Jorani Project

jorani_project

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Jorani
jorani

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jorani Project
1Jorani
Nov 21, 2024
Sep 5, 2018
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startda...Show more
An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startdate or enddate parameter to leaves/validate.Show less
1Jorani Project
1Jorani
Nov 21, 2024
Sep 5, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.