CVE-2026-105173
Received Received - Intake

Cross-Site Scripting in Human Resource Management System

Vulnerability report for CVE-2026-105173, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: VulDB

Description

A flaw has been found in code-projects Human Resource Management 1.0. This affects an unknown part of the file /humanresourcemanagementsystem/src/store/EventStore.php of the component Event Creation. Executing a manipulation of the argument eventSubject can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
code-projects human_resource_management 1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105173 is a Stored Cross-Site Scripting (XSS) vulnerability in the Human Resource Management System 1.0. It occurs in the event creation feature where user input for the eventSubject parameter is not properly sanitized. Attackers can inject malicious scripts via this parameter, which are then stored and executed when other users view the event.

Detection Guidance

To detect this vulnerability, inspect the Human Resource Management System for event creation functionality. Check if the eventSubject parameter in /humanresourcemanagementsystem/src/store/EventStore.php accepts and stores unsanitized HTML input. Test by submitting a payload like <details/open/ontoggle=prompt(origin)> and verify if it executes when viewed by other users.

Impact Analysis

This vulnerability allows attackers to execute arbitrary JavaScript in the context of other users' browsers. Potential impacts include session hijacking, phishing attacks, or theft of sensitive data. Since the payload is stored, any user viewing the compromised event could be affected.

Compliance Impact

Stored XSS can lead to unauthorized access to user data, violating confidentiality requirements under GDPR and HIPAA. It may result in data breaches, triggering compliance violations and potential fines. Organizations must address this to maintain regulatory compliance.

Mitigation Strategies

Implement input validation to reject malicious HTML in the eventSubject parameter. Apply context-aware output encoding using functions like htmlspecialchars. Use a secure HTML sanitizer if HTML input is required. Enforce a restrictive Content Security Policy to limit script execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105173. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart