HRworks 3.36.9 allows XSS via the purpose of a travel-expense report.Referenceshttps://www.hrworks.dehttps://gist.github.com/svennergr/501409fbdb0ef4a8b0f07a26a2815fbb