CVE-2022-45008

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
07/12/2022
Last modified:
23/04/2025

Description

Online Leave Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /leave_system/admin/?page=maintenance/department. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted payload injected into the Name field under the Create New module.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:online_leave_management_system_project:online_leave_management_system:1.0:*:*:*:*:*:*:*