CVE-2025-57117: XSS
A Clickjacking vulnerability exists in Rems' Employee Management System 1.0. This flaw allows remote attackers to execute arbitrary JavaScript on the department.php page by injecting a malicious payload into the Department Name field under Add Department.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57117?
CVE-2025-57117 is classified as a moderate severity Clickjacking vulnerability that can lead to unauthorized JavaScript execution.
How do I fix CVE-2025-57117?
To fix CVE-2025-57117, ensure that proper X-Frame-Options headers are set to prevent clickjacking attacks.
Which software versions are affected by CVE-2025-57117?
CVE-2025-57117 affects Rems Employee Management System version 1.0.
What impact does CVE-2025-57117 have on users?
Users may be exposed to arbitrary JavaScript execution risks, which can lead to data theft and compromise.
Is CVE-2025-57117 easy to exploit?
Yes, CVE-2025-57117 can be easily exploited by remote attackers through a crafted web page.