355
VMScore

CVE-2018-10259

Published: 01/05/2018 Updated: 05/06/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.

Vulnerable Product Search on Vulmon Subscribe to Product

hrsale project hrsale 1.0.2

Exploits

# Exploit Title: HRSALE The Ultimate HRM 102 - Authenticated Cross Site Scripting # Date: 2018-04-23 # Exploit Author: 8bitsec # CVE: CVE-2018-10259 # Vendor Homepage: codecanyonnet/ # Software Link: codecanyonnet/item/hrsale-the-ultimate-hrm/21665619 # Version: 102 # Tested on: [Kali Linux 20 | Mac OS 1013] Release Date: = ...
HRSALE The Ultimate HRM version 102 suffers from a cross site scripting vulnerability ...