CNNVD-202512-2647 Information
CNNVD ID
CNNVD-202512-2647
Related CVE
- CNNVD Published: 2025-12-15
Description (Chinese)
Jorani是法国Benjamin BALET个人开发者的一个休假管理系统。旨在为小型组织提供简单的休假和加班请求工作流程。 Jorani 1.0.3版本存在跨站脚本漏洞,该漏洞源于language参数存在反射型跨站脚本,可能导致注入恶意脚本并窃取用户会话信息。
Description (English)
Jorani is a leave management system for Benjamin BalET personal developers in France. The aim is to provide small organizations with simple leave and overtime request workflows. Version Jorani 1.0.3 has a cross-site script loophole, which stems from the reflection-type cross-site script of the language parameter, which may result in the injection of malicious scripts and the theft of user session information.
Hazard Level
High
Vulnerability Type
跨站脚本
Affected Vendor
个人开发者
Published
2025-12-15
Last Modified
2026-02-24
References
https://jorani.org/ https://www.vulncheck.com/advisories/jorani-cross-site-scripting-vulnerability-via-language-parameter https://www.exploit-db.com/exploits/51715 https://access.redhat.com/security/cve/cve-2023-53870
Share on: