CVE-2024-7269 HIGH

CVE-2024-7269: Stored XSS in ConnX ESP HR Management

Vendor Connx
Product ESP HR Management
Weakness CWE-79 · XSS
Published August 28, 2024
Last update August 28, 2024

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ESP HR Management allows Stored XSS attack. An attacker might inject a script to be run in user's browser. After multiple attempts to contact the vendor we did not receive any answer. The finder provided the information that this issue affects ESP HR Management versions before 6.6.

Key dates

02Disclosure timeline

August 28, 2024 CVE published
August 28, 2024 Record updated