HTML Injection Vulnerability in Applaud HCM 4.0.42+ with XSS Payload

HTML Injection Vulnerability in Applaud HCM 4.0.42+ with XSS Payload

CVE-2019-11033 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

Applaud HCM 4.0.42+ uses HTML tag fields for HTML inputs in a form. This leads to an XSS vulnerability with a payload starting with the <iframe./> substring.

Learn more about our Web Application Penetration Testing UK.