Description
A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function of the file /notice/All_notice of the component Notice Board Management. Such manipulation of the argument Notice Title with the input <svg onload="alert('Stored XSS Triggered by Ashik Mohamed')"> as part of POST leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Problem types
Product status
Timeline
| 2026-06-07: | Vendor acknowledged |
| 2026-06-07: | Advisory disclosed |
| 2026-06-07: | Exploit disclosed |
| 2026-06-07: | VulDB entry created |
| 2026-06-07: | VulDB entry last update |
Credits
Ashik Mohamed
ashikmd7 (VulDB User)
ashikmd7 (VulDB User)
References
vuldb.com/vuln/369111 (VDB-369111 | CodeAstro Human Resource Management System Notice Board Management All_notice cross site scripting)
vuldb.com/vuln/369111/cti (VDB-369111 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-11491 (CVE-2026-11491 | CVE Analysis and Report)
vuldb.com/submit/834747 (Submit #834747 | CodeAstro Human Resource Management System in PHP CodeIgniter 1.0 Cross Site Scripting)
github.com/...kmd0507/CVE/blob/main/CVE-2026-11491/README.md
codeastro.com/