Skip to content

Instantly share code, notes, and snippets.

What would you like to do?
Writeup for CVE-2019-16416


A cross-site-scripting (XSS) issue was discovered in HRworks (classic) 3.36.9. An attacker could exploit this by storing persistent scripts which would lead to unwanted code execution when visiting an affected page.

Export Title

Stored XSS - HRworks (classic) v3.36.9

Vendor Homepage

Exploit Author

Sven Grossmann / Lufthansa Industry Solutions

Contact /







  • 2019-09-16 Disclosure to vendor
  • 2019-09-18 Vendor informed, that the will be fixed with the next product version (v3.37.0)
  • 2019-09-23 Vendor published a fixed product version (v3.37.0)

Proof of Concept

  1. Open HRWorks (classic).
  2. Create new a travel expense report.
  3. Enter as the purpose of the report: test<<img src="." onerror=javascript:alert(1)//
  4. The HTML/JS will be executed when opening the report or showing the report's purpose in the overview.

As investigated further fields of the formular might be vulnerable.

Also see CVE-2019-16416-poc-1.jpg and CVE-2019-16416-poc-2.jpg.


As date of publication all versions above 3.37.0 are save to use.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.