CVE-2020-35753: Persis Human Resource Management Portal

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

The job posting recommendation form in Persis Human Resource Management Portal (Versions 17.2.00 through 17.2.35 and 19.0.00 through 19.0.20), when the "Recommend job posting" function is enabled, allows XSS via the SENDER parameter.

Affected products

  • Persis Human Resource Management Portal: from 17.2.00, up to and including 17.2.35; from 19.0.00, up to and including 19.0.20

Published 2021-01-26. Last modified 2026-06-17.