CVE-2026-105173

Summary

A flaw has been found in code-projects Human Resource Management 1.0. This affects an unknown part of the file /humanresourcemanagementsystem/src/store/EventStore.php of the component Event Creation. Executing a manipulation of the argument eventSubject can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used.

Affected Software

VendorProductVersion RangeStatus
code-projectsHuman Resource Management1.0affected

Weaknesses

  • CWE-79: Cross Site Scripting
  • CWE-94: Code Injection

References