S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 23, 2024

CVE-2018-15917 Scanner

CVE-2018-15917 scanner - Cross-Site Scripting (XSS) vulnerability in Jorani Leave Management System

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-15917
5.4
CVSS

Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Jorani Leave Management System is a web-based application designed to simplify the employee leave management process. It allows organizations to manage employee vacation requests, sick leave, personal leave, and other types of leave that employees can request. The software simplifies the management of large numbers of requests, reducing the administrative burden on HR staff.

CVE-2018-15917 is a vulnerability detected in Jorani version 0.6.5, which allows attackers to inject arbitrary web script or HTML via the language parameter to the session/language field. This means that attackers can enter malicious code into the system, which can then execute upon delivery to the users of the application.

When exploited, this vulnerability can lead to sensitive data being compromised, such as financial, personal, or confidential company information. It could potentially expose user data or credentials, compromising your system's security. Attackers could use the vulnerability to escalate privileges or conduct phishing attacks.

Thanks to the pro features of s4e.io, you can quickly and easily learn about vulnerabilities in your digital assets. This platform can help you stay informed about new security threats and get notified when vulnerabilities are detected, allowing you to take a proactive approach to protecting your business. With this platform, you can be confident that your data is secure and your systems are protected from cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is essential to keep your system up-to-date with the latest software patch. Additionally, you can use a web application firewall to prevent malicious traffic from entering your system, and regularly scan your systems for vulnerabilities and potential security breaches. Some other precautions include:

  • Regularly updating your system with the latest security patches.
  • Implementing strong password policies and two-factor authentication.
  •  Keeping backup copies of essential data and information.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-15917 scanner - Cross-Site Scripting (XSS) vulnerability in Jorani Leave Management System | S4E