Description
Jorani 1.0.3 contains a reflected cross-site scripting vulnerability in the language parameter that allows attackers to inject malicious scripts. Attackers can craft XSS payloads in the language parameter to execute arbitrary JavaScript and potentially steal user session information.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
nu11secur1ty
References
www.exploit-db.com/exploits/51715 (ExploitDB-51715)
jorani.org/ (Jorani Product Webpage)
www.vulncheck.com/...ng-vulnerability-via-language-parameter (VulnCheck Advisory: Jorani 1.0.3 Cross-Site Scripting Vulnerability via Language Parameter)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.