CVE-2025-40683: Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System
Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searccity' parameter in /city.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40683?
CVE-2025-40683 is classified as a critical vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-40683?
To fix CVE-2025-40683, ensure that all user input is properly sanitized and validated, particularly the 'searccity' parameter in city.php.
What are the risks associated with CVE-2025-40683?
The risks of CVE-2025-40683 include unauthorized execution of JavaScript in users' browsers, which can lead to data theft and session hijacking.
Which version of Human Resource Management System is affected by CVE-2025-40683?
CVE-2025-40683 affects Human Resource Management System version 1.0.
What is reflected cross-site scripting in relation to CVE-2025-40683?
Reflected cross-site scripting in CVE-2025-40683 allows attackers to execute malicious JavaScript code in the browser of unsuspecting users.