Executive brief
Patika Global Technologies HumanSuite, a human resources management platform, contains a security vulnerability that could allow attackers to perform cross-site scripting (XSS) and phishing attacks. By tricking a user into clicking a malicious link or visiting a compromised page, an attacker can execute unauthorized scripts in the user's browser session. This could lead to the theft of session information or the display of fraudulent content to employees using the system.
Technical details
A vulnerability exists in Patika Global Technologies HumanSuite (versions prior to 53.21.0) categorized under CWE-79 (Cross-site Scripting), CWE-74 (Injection), and CWE-116 (Improper Encoding). The root cause is the improper neutralization of input during web page generation and failure to correctly escape output used by downstream components. An unauthenticated remote attacker can exploit this by sending specially crafted input that is subsequently rendered in a victim's browser, requiring user interaction (UI:R). Successful exploitation allows for the execution of arbitrary JavaScript or the facilitation of phishing attacks. The issue is resolved in version 53.21.0.
Affected products
- Patika Global Technologies HumanSuite before 53.21.0
Timeline
- 2025-09-16: disclosed
- 2025-09-16: advisory