Vulnerabilities
11 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-67102 | A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands via the entit A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands via the entity parameter. NVD description · AI analysis pending | 7.6 | <1% | PoC |
| — | |
| CVE-2023-48205 | Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails. Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2023-45540 | An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the comment field of the List o An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the comment field of the List of Leave requests page. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2023-2681 | An SQL Injection vulnerability has been found on Jorani version 1.0.0. An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote user, with low privileges, to send queries with malicious SQL code on the "/leaves/validate" path and the “id” parameter, managing to extract arbritary information from the database. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2023-26469 | In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server. In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server. NVD description · AI analysis pending | 9.8 | 83% | PoC ×2 |
| — | |
| CVE-2022-48118 | Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Acronym parameter. Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Acronym parameter. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2022-34132 | Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leaves.php. Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leaves.php. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2018-15917 +1 in the same advisory: …15918 | Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language. NVD description · AI analysis pending | 5.4 | 6% | PoC ×2 |
| — |