Stored XSS Vulnerability in OrangeHRM 4.10
CVE-2022-27107
5.4MEDIUM
What is CVE-2022-27107?
The OrangeHRM version 4.10 is susceptible to a stored XSS vulnerability found in the 'Share Video' section under the 'OrangeBuzz' feature. This issue arises when the 'createVideo[linkAddress]' parameter is manipulated through GET or POST requests, allowing attackers to inject malicious scripts. This vulnerability could enable unauthorized users to execute JavaScript code in the context of other users, potentially compromising sensitive data and user sessions.
