CVE-2022-46903
Published on: Not Yet Published
Last Modified on: 12/15/2022 01:50:00 PM UTC
Certain versions of Websoft Hcm from Websoft contain the following vulnerability:
Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Stored XSS.
- CVE-2022-46903 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 5.4 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Клиентский портал WebSoft | news.websoft.ru text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Websoft | Websoft Hcm | 2021.2.3.327 | All | All | All |
- cpe:2.3:a:websoft:websoft_hcm:2021.2.3.327:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-46903 : Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker… twitter.com/i/web/status/1… | 2022-12-12 21:05:58 |
![]() |
CVE-2022-46903 | 2022-12-12 21:39:42 |