Vulnerabilities > Hrworks

DATE CVE VULNERABILITY TITLE RISK
2019-10-08 CVE-2019-16417 Cross-site Scripting vulnerability in Hrworks 3.36.9
HRworks FLOW 3.36.9 allows XSS via the purpose of a travel-expense report.
network
low complexity
hrworks CWE-79
5.4
2019-10-08 CVE-2019-16416 Cross-site Scripting vulnerability in Hrworks 3.36.9
HRworks 3.36.9 allows XSS via the purpose of a travel-expense report.
network
low complexity
hrworks CWE-79
5.4
2019-09-17 CVE-2019-11559 Cross-site Scripting vulnerability in Hrworks 1.16.1
A reflected Cross-site scripting (XSS) vulnerability in HRworks V 1.16.1 allows remote attackers to inject arbitrary web script or HTML via the URL parameter to the Login component.
network
low complexity
hrworks CWE-79
6.1