HRSALE 2.0.0 allows XSS via the admin/project/projects_calendar set_date parameter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://grimthereaperteam.medium.com/hrsale-v-2-0-0-reflected-cross-site-scripting-17a5617e2c6e | third party advisory exploit |
https://hrsale.com/update_log.php | product |