A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. This affects an unknown part of the file employee.php. The manipulation of the argument Full Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
History

Thu, 06 Mar 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Remyandrade
Remyandrade employee Management System
CPEs cpe:2.3:a:remyandrade:employee_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Remyandrade
Remyandrade employee Management System

Tue, 04 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Mar 2025 04:45:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. This affects an unknown part of the file employee.php. The manipulation of the argument Full Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Title SourceCodester Employee Management System employee.php cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-03-04T14:39:06.206Z

Reserved: 2025-03-03T18:40:31.864Z

Link: CVE-2025-1905

cve-icon Vulnrichment

Updated: 2025-03-04T14:38:55.487Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-04T05:15:14.680

Modified: 2025-03-06T12:17:33.710

Link: CVE-2025-1905

cve-icon Redhat

No data.