CVE-2022-27107
OrangeHRM 4.10 is vulnerable to Stored XSS in the "Share Video" section under "OrangeBuzz" via the GET/POST "createVideo
OrangeHRM 4.10 is vulnerable to Stored XSS in the "Share Video" section under "OrangeBuzz" via the GET/POST "createVideo[linkAddress]" parameter.
MEDIUM · CVSS 5.4
EPSS 0.00191
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0