CVE-2025-1591

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /department.php of the component Department Page. The manipulation of the argument Department Name leads to cross site scripting. The attack can be launched remotely.
References
Link Resource
https://vuldb.com/?ctiid.296575 Permissions Required VDB Entry
https://vuldb.com/?id.296575 VDB Entry Permissions Required
https://vuldb.com/?submit.504048 VDB Entry Third Party Advisory
https://www.sourcecodester.com/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:razormist:employee_management_system:1.0:*:*:*:*:*:*:*

History

28 Feb 2025, 19:18

Type Values Removed Values Added
Summary
  • (es) Se ha detectado una vulnerabilidad en SourceCodester Employee Management System 1.0. Se ha declarado como problemática. Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo /department.php del componente Department Page. La manipulación del argumento Department Name provoca cross site scripting. El ataque se puede ejecutar de forma remota.
First Time Razormist
Razormist employee Management System
CPE cpe:2.3:a:razormist:employee_management_system:1.0:*:*:*:*:*:*:*
References () https://vuldb.com/?ctiid.296575 - () https://vuldb.com/?ctiid.296575 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.296575 - () https://vuldb.com/?id.296575 - VDB Entry, Permissions Required
References () https://vuldb.com/?submit.504048 - () https://vuldb.com/?submit.504048 - VDB Entry, Third Party Advisory
References () https://www.sourcecodester.com/ - () https://www.sourcecodester.com/ - Product

23 Feb 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-23 19:15

Updated : 2025-02-28 19:18


NVD link : CVE-2025-1591

Mitre link : CVE-2025-1591

CVE.ORG link : CVE-2025-1591


JSON object : View

Products Affected

razormist

  • employee_management_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')