A vulnerability was found in SourceCodester Best Employee Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/Operations/Role.php of the component Add Role Page. The manipulation of the argument assign_name/description leads to cross site scripting. The attack may be launched remotely.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-4402 A vulnerability was found in SourceCodester Best Employee Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/Operations/Role.php of the component Add Role Page. The manipulation of the argument assign_name/description leads to cross site scripting. The attack may be launched remotely.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 28 Feb 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Mayurik
Mayurik best Employee Management System
CPEs cpe:2.3:a:mayurik:best_employee_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Mayurik
Mayurik best Employee Management System

Mon, 24 Feb 2025 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 23 Feb 2025 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in SourceCodester Best Employee Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/Operations/Role.php of the component Add Role Page. The manipulation of the argument assign_name/description leads to cross site scripting. The attack may be launched remotely.
Title SourceCodester Best Employee Management System Add Role Page Role.php cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 3.3, 'vector': 'AV:N/AC:L/Au:M/C:N/I:P/A:N'}

cvssV3_0

{'score': 2.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-02-24T12:05:21.364Z

Reserved: 2025-02-22T18:57:08.244Z

Link: CVE-2025-1592

cve-icon Vulnrichment

Updated: 2025-02-24T12:05:16.317Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-23T20:15:08.243

Modified: 2025-02-28T18:33:35.540

Link: CVE-2025-1592

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.