Mani Sashank

2 exploits Active since Jan 2025
CVE-2024-46073 WRITEUP MEDIUM WRITEUP
IceHRM v32.4.0.OS - XSS
A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization of the "next" parameter, which is included in the application's response without adequate escaping. An attacker can exploit this flaw by tricking a user into visiting a specially crafted URL, causing the execution of arbitrary JavaScript code in the context of the victim's browser. The issue occurs even though the application has sanitization mechanisms in place.
CVSS 6.1
CVE-2024-51392 WRITEUP HIGH WRITEUP
OpenKnowledgeMaps Headstart v7 - Privilege Escalation
An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the getPDF.php component
CVSS 8.8