Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Oct 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in code-projects Human Resource Management 1.0. This affects an unknown part of the file /humanresourcemanagementsystem/src/store/EventStore.php of the component Event Creation. Executing a manipulation of the argument eventSubject can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. | |
| Title | code-projects Human Resource Management Event Creation EventStore.php cross site scripting | |
| First Time appeared |
Code-projects
Code-projects human Resource Management |
|
| Weaknesses | CWE-79 CWE-94 |
|
| CPEs | cpe:2.3:a:code-projects:human_resource_management:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Code-projects
Code-projects human Resource Management |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-05T13:20:26.432Z
Reserved: 2026-10-04T08:34:20.954Z
Link: CVE-2026-105173
Updated: 2026-10-05T13:20:19.886Z
Status : Received
Published: 2026-10-05T01:16:27.847
Modified: 2026-10-05T14:17:17.280
Link: CVE-2026-105173
No data.
OpenCVE Enrichment
Updated: 2026-10-05T02:30:08Z