XSS Vulnerability in Persis Human Resource Management Portal's Job Posting Recommendation Form

XSS Vulnerability in Persis Human Resource Management Portal's Job Posting Recommendation Form

CVE-2020-35753 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

The job posting recommendation form in Persis Human Resource Management Portal (Versions 17.2.00 through 17.2.35 and 19.0.00 through 19.0.20), when the "Recommend job posting" function is enabled, allows XSS via the SENDER parameter.

Learn more about our Web Application Penetration Testing UK.