CVE-2025-40686

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'employeeid' parameter in/detailview.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oretnom23:human_resource_management_system:1.0:*:*:*:*:*:*:*

History

04 Aug 2025, 20:59

Type Values Removed Values Added
CPE cpe:2.3:a:oretnom23:human_resource_management_system:1.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
First Time Oretnom23 human Resource Management System
Oretnom23
Summary
  • (es) Cross-Site Scripting (XSS) reflejado en Human Resource Management System version 1.0. Esta vulnerabilidad podría permitir que un atacante ejecute código JavaScript en el navegador de la víctima enviando una URL maliciosa a través del parámetro 'employeeid' en/detailview.php.
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-human-resource-management-system - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-human-resource-management-system - Third Party Advisory

29 Jul 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-29 13:15

Updated : 2025-08-04 20:59


NVD link : CVE-2025-40686

Mitre link : CVE-2025-40686

CVE.ORG link : CVE-2025-40686


JSON object : View

Products Affected

oretnom23

  • human_resource_management_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')