Stored XSS Vulnerability in Ice Hrm 30.0.0.OS Allows Cookie Theft via Crafted First Name Field Payload

Stored XSS Vulnerability in Ice Hrm 30.0.0.OS Allows Cookie Theft via Crafted First Name Field Payload

CVE-2022-25015 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

A stored cross-site scripting (XSS) vulnerability in Ice Hrm 30.0.0.OS allows attackers to steal cookies via a crafted payload inserted into the First Name field.

Learn more about our Web Application Penetration Testing UK.