CVE-2025-40975 - Multiple vulnerabilities in WorkDo products
CVE ID : CVE-2025-40975
Published : Jan. 12, 2026, 12:16 p.m. | 2 hours, 53 minutes ago
Description : Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's HRMGo, consisting of a lack of proper validation of user input by sending a POST request to ‘/hrmgo/ticket/changereply’, using the ‘description’ parameter.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Jan. 12, 2026, 12:16 p.m. | 2 hours, 53 minutes ago
Description : Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's HRMGo, consisting of a lack of proper validation of user input by sending a POST request to ‘/hrmgo/ticket/changereply’, using the ‘description’ parameter.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...