CVE-2026-105173: code-projects Human Resource Management Event Creation EventStore.php cross site scripting
A flaw has been found in code-projects Human Resource Management 1.0. This affects an unknown part of the file /humanresourcemanagementsystem/src/store/EventStore.php of the component Event Creation. Executing a manipulation of the argument eventSubject can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
The issue affects code-projects Human Resource Management 1.0 in the Event Creation component, specifically the EventStore.php path handling the eventSubject argument.
What does an attacker need to exploit this issue?
An attacker can launch the attack remotely but needs low-privileged access and user interaction. Exploitation involves manipulating the eventSubject argument to trigger cross-site scripting.
Is public exploit code available?
Yes. The exploit has been published and may be used.