Vulnerability CVE-2023-27121


Published: 2023-10-04

Description:
A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasant Password Server v7.11.41.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cronString parameter.

 References:
https://www.mdsec.co.uk/2023/09/the-not-so-pleasant-password-manager/
https://www.nuget.org/packages/CronExpressionDescriptor/2.9.0
https://pleasantpasswords.com/download

Copyright 2026, cxsecurity.com

 

Back to Top