Filtered by vendor Jorani Subscriptions
Filtered by product Leave Management System Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-53870 1 Jorani 2 Jorani, Leave Management System 2026-03-05 N/A
Jorani 1.0.3 contains a reflected cross-site scripting vulnerability in the language parameter that allows attackers to inject malicious scripts. Attackers can craft XSS payloads in the language parameter to execute arbitrary JavaScript and potentially steal user session information.
CVE-2023-48205 1 Jorani 1 Leave Management System 2024-11-21 5.3 Medium
Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails.
CVE-2023-45540 1 Jorani 1 Leave Management System 2024-11-21 6.5 Medium
An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the comment field of the List of Leave requests page.