VYPR

Jorani

by Jorani Project

CVEs (2)

  • CVE-2018-15917MedSep 5, 2018
    risk 0.39cvss 5.4epss 0.06

    Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.

  • CVE-2018-15918MedSep 5, 2018
    risk 0.38cvss 5.4epss 0.03

    An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startdate or enddate parameter to leaves/validate.