Description
A flaw has been found in code-projects Human Resource Management 1.0. This affects an unknown part of the file /humanresourcemanagementsystem/src/store/EventStore.php of the component Event Creation. Executing a manipulation of the argument eventSubject can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used.
Published: 2026-10-05
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Remote Cross‑Site Scripting (XSS)
Action: Apply Patch
AI Analysis

Impact

A cross‑site scripting flaw exists in the Human Resource Management system of code‑projects. By manipulating the eventSubject argument in the EventStore.php file, an attacker can inject malicious scripts that will execute in the browsers of any logged‑in user who views the affected event. The flaw allows unauthenticated or authenticated users to induce the application to render unsanitized user input, potentially revealing session cookies or other sensitive data, or delivering malicious payloads to end users. This weakness is an instance of CWE‑79 and is accompanied by a secondary code‑injection concern (CWE‑94).

Affected Systems

The vulnerability is present in code‑projects Human Resource Management version 1.0, specifically within the Event Creation component of the EventStore.php module. No other affected versions or components are documented, and the vulnerable location is referenced as /humanresourcemanagementsystem/src/store/EventStore.php. Users running this software should check their installation against this file path and confirm they are on the known vulnerable release.

Risk and Exploitability

The CVSS score of 5.1 places the issue in a moderate severity range. The EPSS score is not available, so the immediate exploitation probability is unknown, but the vulnerability is listed as exploitable with a published exploit. Attackers can launch the exploit remotely by sending specially crafted eventSubject values. The issue is not currently tracked in CISA's KEV catalog, indicating it has not been confirmed as actively exploited in the wild yet. Nonetheless, given the remote nature of the attack and the dependence on user interaction, the risk is non‑negligible.

Generated by OpenCVE AI on October 5, 2026 at 02:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Confirm whether code‑projects has released an updated version of Human Resource Management that resolves the XSS flaw and upgrade to that version if possible.
  • In the absence of a vendor patch, implement defensive input handling by validating and encoding the eventSubject parameter on both client and server sides, ensuring that any embedded script logic cannot be executed in the browser.
  • Restrict the override or creation of events to highly privileged administrators, removing the feature from general user accounts to reduce the potential attack surface.

Generated by OpenCVE AI on October 5, 2026 at 02:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 01:00:00 +0000

Type Values Removed Values Added
Description A flaw has been found in code-projects Human Resource Management 1.0. This affects an unknown part of the file /humanresourcemanagementsystem/src/store/EventStore.php of the component Event Creation. Executing a manipulation of the argument eventSubject can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used.
Title code-projects Human Resource Management Event Creation EventStore.php cross site scripting
First Time appeared Code-projects
Code-projects human Resource Management
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:code-projects:human_resource_management:*:*:*:*:*:*:*:*
Vendors & Products Code-projects
Code-projects human Resource Management
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Code-projects Human Resource Management
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T00:15:14.925Z

Reserved: 2026-10-04T08:34:20.954Z

Link: CVE-2026-105173

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T01:16:27.847

Modified: 2026-10-05T01:16:27.847

Link: CVE-2026-105173

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T02:30:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')