CVE-2020-35753
Summary
| CVE | CVE-2020-35753 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-26 18:15:00 UTC |
| Updated | 2022-10-07 02:24:00 UTC |
| Description | The job posting recommendation form in Persis Human Resource Management Portal (Versions 17.2.00 through 17.2.35 and 19.0.00 through 19.0.20), when the "Recommend job posting" function is enabled, allows XSS via the SENDER parameter. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | - | All | All | All |
| Operating System | Linux | Linux Kernel | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Application | Persis | Human Resource Management Portal | All | All | All | All |
| Application | Persis | Human Resource Management Portal | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Persis High-Level Human Resource Software - Online Applicant Portal Security Advisory (CVE-2020-35753) - slashcrypto's page | MISC | slashcrypto.org | |
| it.sec Research Team findet unbekannte Schwachstelle in Persis Online Bewerberportal / it.sec blog / Aktuelles & Termine / Home - it.sec Home | MISC | it-sec.de | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.