PoC Index

CVE-2018-12234

MEDIUM 6.1EPSS 2.9%

A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the flexiportal/GeneralInfo.aspx strAction parameter.

CVSS v3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
2.95% chance of exploitation in the next 30 days, 86th percentile
Published
2018-09-06
Updated
2026-03-02

ExploitDB entries (1)

References

Related