Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple stored cross-site scripting (XSS) vulnerabilities in the Future Goals function of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Goal Name, Goal Notes, Action Step Name, Action Step Description, Note Name, and Goal Description parameters. The patched version is PP-Release-6.3.2.0.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
HR Performance Solutions Performance Pro 安全漏洞
Vulnerability Description
HR Performance Solutions Performance Pro是美国HR Performance公司的一款员工绩效管理平台。 Performance Pro v3.19.17版本存在安全漏洞,该漏洞源于Future Goals功能中对Goal Name、Goal Notes、Action Step Name、Action Step Description、Note Name和Goal Description参数的特制输入处理不当,可能导致存储型跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A