Record summary

CVE-2018-12234 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.

Description

A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the flexiportal/GeneralInfo.aspx strAction parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBAdrenalin Core HCM 5.4.0 - 'strAction' Reflected Cross-Site ScriptingExploitDB exploitby Cy83rl0ggerNot analyzed1 file
ExploitDB

PoC details

References

5