Stored XSS Vulnerability in OrangeHRM 4.10
CVE-2022-27107

5.4MEDIUM

Key Information:

Vendor

Orangehrm

Status
Vendor
CVE Published:
6 April 2022

What is CVE-2022-27107?

The OrangeHRM version 4.10 is susceptible to a stored XSS vulnerability found in the 'Share Video' section under the 'OrangeBuzz' feature. This issue arises when the 'createVideo[linkAddress]' parameter is manipulated through GET or POST requests, allowing attackers to inject malicious scripts. This vulnerability could enable unauthorized users to execute JavaScript code in the context of other users, potentially compromising sensitive data and user sessions.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.