First published: Fri Mar 21 2025(Updated: )
A vulnerability was found in code-projects Human Resource Management System 1.0.1. It has been classified as problematic. Affected is the function UpdateRecruitmentById of the file \handler\recruitment.go. The manipulation of the argument c leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Human Resource Management System | ||
code-projects Human Resource Management | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2590 has been classified as problematic due to its potential for cross-site scripting vulnerabilities.
To fix CVE-2025-2590, update the application to the latest version that includes patches for this vulnerability.
CVE-2025-2590 affects the function UpdateRecruitmentById in the file \handler\recruitment.go.
CVE-2025-2590 poses a risk of cross-site scripting attacks, which could allow attackers to execute malicious scripts in users' browsers.
CVE-2025-2590 affects version 1.0.1 of the code-projects Human Resource Management System.