Sceawere
Vulnerability Detail
CVE-2026-105173UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in EventStore.php
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.5
- Creation Date
- 17h ago
- Vendor
- code-projects
- Product
- Human Resource Management
- Attack Type
- Cross Site Scripting
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in code-projects Human Resource Management 1.0. This affects an unknown part of the file /humanresourcemanagementsystem/src/store/EventStore.php of the component Event Creation. Executing a manipulation of the argument eventSubject can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.5",
"pubDate": "2026-10-05T01:16:27.847Z",
"pubdate": "2026-10-05T01:16:27.847Z",
"executiveSummary": "A Cross-Site Scripting (XSS) vulnerability has been identified in the Human Resource Management 1.0 system.\nThe vulnerability resides within the Event Creation component, specifically affecting the /humanresourcemanagementsystem/src/store/EventStore.php file.\nThe flaw allows a remote, unauthenticated attacker to inject malicious scripts into the application via the eventSubject argument.\nSuccessful exploitation results in the execution of arbitrary JavaScript in the context of the victim's browser session.\nThis can lead to session hijacking, unauthorized actions performed on behalf of the user, and the exfiltration of sensitive information.\nGiven that exploit code is publicly available, the risk to the availability, integrity, and confidentiality of the application is high, necessitating immediate remediation efforts.",
"technicalDetails": "The vulnerability is categorized as a Cross-Site Scripting (XSS) flaw, specifically manifesting as a reflected XSS attack within the Event Creation functionality of Human Resource Management 1.0.\nThe root cause is the improper sanitization and validation of user-supplied input provided via the eventSubject parameter in the /humanresourcemanagementsystem/src/store/EventStore.php file before it is rendered back to the user within the browser.\nThe attack flow begins when an attacker crafts a malicious URL containing a JavaScript payload within the eventSubject argument. When an unsuspecting user, such as an HR administrator, is induced to click this link, the application processes the request.\nBecause the server-side code in EventStore.php fails to neutralize control characters or encode output appropriately, the application reflects the malicious script directly into the HTML response document.\nUpon receipt of the crafted HTTP response, the victim's browser interprets the injected payload as legitimate application code and executes it within the security context of the origin domain.\nThis execution environment permits the attacker to bypass Same-Origin Policy (SOP) restrictions, enabling the theft of sensitive session cookies, local storage data, or the CSRF tokens required to authorize state-changing requests.\nFurthermore, the attacker can manipulate the Document Object Model (DOM) to perform UI redressing, capture keystrokes, or redirect the user to malicious third-party domains.\nSince the vulnerability is exploitable remotely, an attacker does not require direct access to the server infrastructure, significantly expanding the attack surface.\nThe publication of existing exploit code facilitates ease of exploitation for less sophisticated actors, as they can leverage pre-existing scripts to weaponize the input field without requiring original research into the application's underlying architecture.\nPost-exploitation impact includes full account compromise, unauthorized access to sensitive employee HR data, and potentially unauthorized modification of system events or configurations managed by the vulnerable EventStore.php component."
}