Sceawere

Vulnerability Detail

CVE-2026-105188UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Reflected XSS in Human Resource Management System

Vulnerability Metadata

Severity
Low
Score / CVSS
3.5
Creation Date
13h ago
Vendor
code-projects
Product
Human Resource Management System
Attack Type
Cross Site Scripting
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in code-projects Human Resource Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /views/admin/liveEventHistory.php of the component Live Event History. The manipulation of the argument eventSubject results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.5",
  "pubDate": "2026-10-05T05:17:02.660Z",
  "pubdate": "2026-10-05T05:17:02.660Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists within the Human Resource Management System 1.0, specifically impacting the Live Event History component.\nThe vulnerability is located in the /views/admin/liveEventHistory.php file and is triggered via improper sanitization of the eventSubject argument.\nThis flaw allows remote, unauthenticated or authenticated attackers (depending on access to the admin interface) to inject malicious scripts into the web application's response.\nWhen a user or administrator interacts with the manipulated URL, the injected script executes within the context of their session, potentially leading to unauthorized data access, session hijacking, or defacement.\nThe risk is elevated due to the public availability of an exploit, necessitating immediate remediation to prevent exploitation.",
  "technicalDetails": "The vulnerability is a classic Reflected Cross-Site Scripting (XSS) flaw occurring due to the application's failure to properly sanitize, validate, or encode user-supplied input before reflecting it back to the end-user's browser.\nThe specific injection vector is the eventSubject parameter within the /views/admin/liveEventHistory.php file. The application accepts the value of this parameter and embeds it directly into the HTML response document rendered for the user.\nThe attack flow begins when an attacker crafts a malicious URL containing a JavaScript payload within the eventSubject argument. For instance, an attacker could provide an input such as <script>alert('XSS')</script> or other event handlers like onload or onerror, often obfuscated to bypass basic filters.\nOnce the victim accesses this crafted URL, the server processes the input and returns an HTTP response containing the unencoded, malicious payload. The victim's browser, interpreting the server's response, treats the payload as legitimate script content belonging to the application's origin.\nBecause the execution happens within the browser of the victim, the script inherits the application's privileges. This allows the attacker to perform actions on behalf of the victim, such as stealing session cookies, capturing sensitive information displayed on the page, or redirecting the user to malicious sites.\nThe vulnerability resides in the server-side code of the Live Event History component, which fails to employ context-aware output encoding. Since the output is reflected inside an HTML context, the application should have ensured that all special characters are converted to their corresponding HTML entities (e.g., converting '<' to '&lt;' and '>' to '&gt;') before rendering.\nAs the exploit is publicly disclosed, the barrier to entry for potential attackers is significantly lowered, allowing even low-skilled threat actors to weaponize the vulnerability against deployed instances of Human Resource Management System 1.0."
}
CVE-2026-105188: Reflected XSS in Human Resource Management System (LOW Severity, CVSS: 3.5) | Sceawere