Vulnerabilities > Hrsale

DATE CVE VULNERABILITY TITLE RISK
2020-11-24 CVE-2020-29053 Cross-site Scripting vulnerability in Hrsale 2.0.0
HRSALE 2.0.0 allows XSS via the admin/project/projects_calendar set_date parameter.
network
hrsale CWE-79
4.3
2020-10-29 CVE-2020-27993 Path Traversal vulnerability in Hrsale 2.0.0
Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files.
network
low complexity
hrsale CWE-22
5.0