CVE-2022-46903: Websoft Hcm

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Stored XSS.

Affected products

  • Websoft Websoft Hcm: version 2021.2.3.327 only

Published 2022-12-12. Last modified 2026-06-17.