CVE-2025-1905: SourceCodester Employee Management System employee.php cross site scripting
A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. This affects an unknown part of the file employee.php. The manipulation of the argument Full Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1905?
CVE-2025-1905 is classified as a problematic vulnerability affecting the SourceCodester Employee Management System.
How do I fix CVE-2025-1905?
To fix CVE-2025-1905, sanitize user inputs to prevent cross-site scripting vulnerabilities in the employee.php file.
What type of vulnerability is CVE-2025-1905?
CVE-2025-1905 is a cross-site scripting (XSS) vulnerability.
Which software is affected by CVE-2025-1905?
CVE-2025-1905 affects the SourceCodester Employee Management System version 1.0.
What is the attack vector for CVE-2025-1905?
CVE-2025-1905 can be exploited through manipulation of the Full Name argument in the employee.php file.