CVE-2022-46905: Websoft Hcm
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an unauthenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Reflected XSS.
Affected products
- Websoft Websoft Hcm: version 2021.2.3.327 only
Published 2022-12-12. Last modified 2026-06-17.