Description
A vulnerability, which was classified as problematic, has been found in code-projects Employee Record System 1.0. Affected by this issue is some unknown functionality of the file dashboard\edit_employee.php. The manipulation of the argument employeed_id/first_name/middle_name/last_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Eine problematische Schwachstelle wurde in code-projects Employee Record System 1.0 entdeckt. Hierbei geht es um eine nicht exakt ausgemachte Funktion der Datei dashboard\edit_employee.php. Durch Beeinflussen des Arguments employeed_id/first_name/middle_name/last_name mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung.
Problem types
Product status
Timeline
| 2025-05-15: | Advisory disclosed |
| 2025-05-15: | VulDB entry created |
| 2025-05-15: | VulDB entry last update |
Credits
LonTan0 (VulDB User)
References
vuldb.com/?id.309044 (VDB-309044 | code-projects Employee Record System edit_employee.php cross site scripting)
vuldb.com/?ctiid.309044 (VDB-309044 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.570965 (Submit #570965 | code-projects Employee Record System 1.0 Cross Site Scripting)
github.com/.../CVE/blob/main/employee-record-system-xss1.pdf
code-projects.org/