CVE-2025-40683

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searccity' parameter in /city.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oretnom23:human_resource_management_system:1.0:*:*:*:*:*:*:*

History

04 Aug 2025, 20:59

Type Values Removed Values Added
CPE cpe:2.3:a:oretnom23:human_resource_management_system:1.0:*:*:*:*:*:*:*
First Time Oretnom23 human Resource Management System
Oretnom23
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-human-resource-management-system - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-human-resource-management-system - Third Party Advisory
Summary
  • (es) Se detectó un ataque de Cross-Site Scripting (XSS) reflejado en Human Resource Management System version 1.0. Esta vulnerabilidad podría permitir que un atacante ejecute código JavaScript en el navegador de la víctima enviando una URL maliciosa a través del parámetro "searccity" en /city.php.

29 Jul 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-29 13:15

Updated : 2025-08-04 20:59


NVD link : CVE-2025-40683

Mitre link : CVE-2025-40683

CVE.ORG link : CVE-2025-40683


JSON object : View

Products Affected

oretnom23

  • human_resource_management_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')