Partner Software's Partner Software application and...
Unreviewed
Published
Aug 2, 2025
to the GitHub Advisory Database
•
Updated Aug 2, 2025
Description
Published by the National Vulnerability Database
Aug 2, 2025
Published to the GitHub Advisory Database
Aug 2, 2025
Last updated
Aug 2, 2025
Partner Software's Partner Software application and Partner Web application allows an authenticated user to add notes on the 'Notes' page when viewing a job but does not completely sanitize input, making it possible to add notes with HTML tags and JavaScript, enabling an attacker to add a note containing malicious JavaScript, leading to stored XSS (cross-site scripting).
References