CVE-2025-40686: Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System
Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'employeeid' parameter in/detailview.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40686?
The severity of CVE-2025-40686 is considered high due to its potential to allow JavaScript code execution in a victim's browser.
How can I fix CVE-2025-40686?
To fix CVE-2025-40686, ensure proper input validation and sanitation for the 'employeeid' parameter in detailview.php.
Who is affected by CVE-2025-40686?
CVE-2025-40686 affects users of the Human Resource Management System version 1.0.
What type of vulnerability is CVE-2025-40686?
CVE-2025-40686 is a reflected cross-site scripting (XSS) vulnerability.
What is the potential impact of CVE-2025-40686?
The potential impact of CVE-2025-40686 is that attackers can execute arbitrary JavaScript in victims' browsers, leading to session hijacking or data theft.