Reflected XSS Vulnerability in IceHRM by Gamonoid
CVE-2024-46073
6.1MEDIUM
What is CVE-2024-46073?
A reflected Cross-Site Scripting (XSS) vulnerability is present in the login page of IceHRM v32.4.0.OS, arising from improper sanitization of the 'next' parameter. This flaw allows an attacker to craft a malicious URL that, when visited by a user, executes arbitrary JavaScript within the context of the victim's browser. Despite existing sanitization mechanisms, the vulnerability exposes users to potential attacks, making it crucial for organizations using this software version to implement mitigation strategies.
