XSS Vulnerability in Persis Human Resource Management Portal's Job Posting Recommendation Form
CVE-2020-35753 · MEDIUM Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The job posting recommendation form in Persis Human Resource Management Portal (Versions 17.2.00 through 17.2.35 and 19.0.00 through 19.0.20), when the "Recommend job posting" function is enabled, allows XSS via the SENDER parameter.
Learn more about our Web Application Penetration Testing UK.