Reflected XSS Vulnerability in IceHRM by Gamonoid
CVE-2024-46073

6.1MEDIUM

Key Information:

Vendor

Gamonoid

Status
Vendor
CVE Published:
6 January 2025

What is CVE-2024-46073?

A reflected Cross-Site Scripting (XSS) vulnerability is present in the login page of IceHRM v32.4.0.OS, arising from improper sanitization of the 'next' parameter. This flaw allows an attacker to craft a malicious URL that, when visited by a user, executes arbitrary JavaScript within the context of the victim's browser. Despite existing sanitization mechanisms, the vulnerability exposes users to potential attacks, making it crucial for organizations using this software version to implement mitigation strategies.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.