Sceawere

Vulnerability Detail

CVE-2026-105173UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Reflected XSS in EventStore.php

Vulnerability Metadata

Severity
Low
Score / CVSS
3.5
Creation Date
17h ago
Vendor
code-projects
Product
Human Resource Management
Attack Type
Cross Site Scripting
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in code-projects Human Resource Management 1.0. This affects an unknown part of the file /humanresourcemanagementsystem/src/store/EventStore.php of the component Event Creation. Executing a manipulation of the argument eventSubject can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.5",
  "pubDate": "2026-10-05T01:16:27.847Z",
  "pubdate": "2026-10-05T01:16:27.847Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) vulnerability has been identified in the Human Resource Management 1.0 system.\nThe vulnerability resides within the Event Creation component, specifically affecting the /humanresourcemanagementsystem/src/store/EventStore.php file.\nThe flaw allows a remote, unauthenticated attacker to inject malicious scripts into the application via the eventSubject argument.\nSuccessful exploitation results in the execution of arbitrary JavaScript in the context of the victim's browser session.\nThis can lead to session hijacking, unauthorized actions performed on behalf of the user, and the exfiltration of sensitive information.\nGiven that exploit code is publicly available, the risk to the availability, integrity, and confidentiality of the application is high, necessitating immediate remediation efforts.",
  "technicalDetails": "The vulnerability is categorized as a Cross-Site Scripting (XSS) flaw, specifically manifesting as a reflected XSS attack within the Event Creation functionality of Human Resource Management 1.0.\nThe root cause is the improper sanitization and validation of user-supplied input provided via the eventSubject parameter in the /humanresourcemanagementsystem/src/store/EventStore.php file before it is rendered back to the user within the browser.\nThe attack flow begins when an attacker crafts a malicious URL containing a JavaScript payload within the eventSubject argument. When an unsuspecting user, such as an HR administrator, is induced to click this link, the application processes the request.\nBecause the server-side code in EventStore.php fails to neutralize control characters or encode output appropriately, the application reflects the malicious script directly into the HTML response document.\nUpon receipt of the crafted HTTP response, the victim's browser interprets the injected payload as legitimate application code and executes it within the security context of the origin domain.\nThis execution environment permits the attacker to bypass Same-Origin Policy (SOP) restrictions, enabling the theft of sensitive session cookies, local storage data, or the CSRF tokens required to authorize state-changing requests.\nFurthermore, the attacker can manipulate the Document Object Model (DOM) to perform UI redressing, capture keystrokes, or redirect the user to malicious third-party domains.\nSince the vulnerability is exploitable remotely, an attacker does not require direct access to the server infrastructure, significantly expanding the attack surface.\nThe publication of existing exploit code facilitates ease of exploitation for less sophisticated actors, as they can leverage pre-existing scripts to weaponize the input field without requiring original research into the application's underlying architecture.\nPost-exploitation impact includes full account compromise, unauthorized access to sensitive employee HR data, and potentially unauthorized modification of system events or configurations managed by the vulnerable EventStore.php component."
}
CVE-2026-105173: Reflected XSS in EventStore.php (LOW Severity, CVSS: 3.5) | Sceawere