CVE-2025-4744: code-projects Employee Record System edit_employee.php cross site scripting
A vulnerability, which was classified as problematic, has been found in code-projects Employee Record System 1.0. Affected by this issue is some unknown functionality of the file dashboard\editemployee.php. The manipulation of the argument employeedid/firstname/middlename/lastname leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4744?
CVE-2025-4744 is classified as problematic, indicating a significant vulnerability that requires attention.
How do I fix CVE-2025-4744?
To fix CVE-2025-4744, ensure that the Employee Record System is updated to the latest version and implement proper input validation for the affected parameters.
What systems are affected by CVE-2025-4744?
CVE-2025-4744 affects version 1.0 of the code-projects Employee Record System.
What types of attacks can be executed due to CVE-2025-4744?
Exploitation of CVE-2025-4744 may allow unauthorized access or manipulation of employee records through the affected functionality.
Is there a known exploit for CVE-2025-4744?
As of now, there may be exploitation scenarios for CVE-2025-4744, and it is advisable to monitor for updates regarding active attacks.