Impact
A cross‑site scripting flaw exists in the Human Resource Management system of code‑projects. By manipulating the eventSubject argument in the EventStore.php file, an attacker can inject malicious scripts that will execute in the browsers of any logged‑in user who views the affected event. The flaw allows unauthenticated or authenticated users to induce the application to render unsanitized user input, potentially revealing session cookies or other sensitive data, or delivering malicious payloads to end users. This weakness is an instance of CWE‑79 and is accompanied by a secondary code‑injection concern (CWE‑94).
Affected Systems
The vulnerability is present in code‑projects Human Resource Management version 1.0, specifically within the Event Creation component of the EventStore.php module. No other affected versions or components are documented, and the vulnerable location is referenced as /humanresourcemanagementsystem/src/store/EventStore.php. Users running this software should check their installation against this file path and confirm they are on the known vulnerable release.
Risk and Exploitability
The CVSS score of 5.1 places the issue in a moderate severity range. The EPSS score is not available, so the immediate exploitation probability is unknown, but the vulnerability is listed as exploitable with a published exploit. Attackers can launch the exploit remotely by sending specially crafted eventSubject values. The issue is not currently tracked in CISA's KEV catalog, indicating it has not been confirmed as actively exploited in the wild yet. Nonetheless, given the remote nature of the attack and the dependence on user interaction, the risk is non‑negligible.
OpenCVE Enrichment