Reflective Cross Site Scripting in HRIS software (HRMS product)
A vulnerability in the HRIS software (HRMS product) leads to a reflective cross site scripting.
Details about vulnerability
There is an improper neutralization of input during web page generation in the F_NavForm parameter.
Version vulnerable
Versions belows 4.17 are vulnerable. This vulnerability is fixed in version 4.17.
Fixes
We are not aware of any fixes. The vendor was contacted the 9th January 2015 for more information.
CVE
CVE-2015-1035
Acknowledgement
CIRCL would like to thank the reporter.
Classification of this document
TLP:WHITE information may be distributed without restriction, subject to copyright controls.
Revision
- Version 1.0 - TLP:WHITE - First version (20150629)