packetstormsecurity.com
http://packetstormsecurity.com/files/155231/Adrenalin-Core-HCM-5.4.0-Cross-Site-Scripting.html CVE-2018-12234
MEDIUM
Adrenalin Core HCM 5.4.0 - 'strAction' Reflected Cross-Site Scripting
Record summary
CVE-2018-12234 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the flexiportal/GeneralInfo.aspx strAction parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAdrenalin Core HCM 5.4.0 - 'strAction' Reflected Cross-Site ScriptingExploitDB exploitby Cy83rl0ggerNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-12234 knowcybersec.com
https://www.knowcybersec.com/2018/09/first-cve-2018-12234-reflected-XSS.html securethy.com
https://www.securethy.com/2018/09/first-cve-2018-12234-reflected-XSS.html thecysec.in
https://www.thecysec.in/2020/04/xxs-adrenalin-generalinfo-cve-id.html