- EPSS 0.02%
- Veröffentlicht 17.02.2026 20:22:04
- Zuletzt bearbeitet 18.02.2026 17:51:53
A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands via the entity parameter.
CVE-2023-53870
- EPSS 0.07%
- Veröffentlicht 15.12.2025 20:28:14
- Zuletzt bearbeitet 16.12.2025 14:10:11
Jorani 1.0.3 contains a reflected cross-site scripting vulnerability in the language parameter that allows attackers to inject malicious scripts. Attackers can craft XSS payloads in the language parameter to execute arbitrary JavaScript and potential...
CVE-2023-2681
- EPSS 0.57%
- Veröffentlicht 03.10.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 07:59:04
An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote user, with low privileges, to send queries with malicious SQL code on the "/leaves/validate" path and the “id” parameter, managin...
CVE-2023-26469
- EPSS 92.66%
- Veröffentlicht 17.08.2023 19:15:12
- Zuletzt bearbeitet 21.11.2024 07:51:34
In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
CVE-2022-48118
- EPSS 0.37%
- Veröffentlicht 27.01.2023 20:15:14
- Zuletzt bearbeitet 28.03.2025 16:15:24
Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Acronym parameter.
CVE-2022-34132
- EPSS 0.71%
- Veröffentlicht 28.06.2022 00:15:08
- Zuletzt bearbeitet 21.11.2024 07:08:55
Benjamin BALET Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leaves.php.
CVE-2022-34133
- EPSS 0.22%
- Veröffentlicht 28.06.2022 00:15:08
- Zuletzt bearbeitet 21.11.2024 07:08:55
Benjamin BALET Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Comment parameter at application/controllers/Leaves.php.
CVE-2022-34134
- EPSS 0.12%
- Veröffentlicht 28.06.2022 00:15:08
- Zuletzt bearbeitet 21.11.2024 07:08:55
Benjamin BALET Jorani v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /application/controllers/Users.php.