CNNVD-202512-2647 Information

CNNVD ID

CNNVD-202512-2647

CVE-2023-53870

  • CNNVD Published: 2025-12-15

Description (Chinese)

Jorani是法国Benjamin BALET个人开发者的一个休假管理系统。旨在为小型组织提供简单的休假和加班请求工作流程。 Jorani 1.0.3版本存在跨站脚本漏洞,该漏洞源于language参数存在反射型跨站脚本,可能导致注入恶意脚本并窃取用户会话信息。

Description (English)

Jorani is a leave management system for Benjamin BalET personal developers in France. The aim is to provide small organizations with simple leave and overtime request workflows. Version Jorani 1.0.3 has a cross-site script loophole, which stems from the reflection-type cross-site script of the language parameter, which may result in the injection of malicious scripts and the theft of user session information.

Hazard Level

High

Vulnerability Type

跨站脚本

Affected Vendor

个人开发者

Published

2025-12-15

Last Modified

2026-02-24

References

https://jorani.org/ https://www.vulncheck.com/advisories/jorani-cross-site-scripting-vulnerability-via-language-parameter https://www.exploit-db.com/exploits/51715 https://access.redhat.com/security/cve/cve-2023-53870

Share on: