PT-2026-35364 · Code Projects · Employee Management System

Ssl_Seven_Security_Lab_Wangzhiqiang_Zhanxiuchen

·

Published

2026-04-27

·

Updated

2026-04-27

·

CVE-2026-7095

CVSS v3.1

4.3

Medium

AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
A vulnerability was identified in code-projects Employee Management System 1.0. This affects an unknown part of the file 370project/edit.php. The manipulation of the argument ID leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7095

Affected Products

Employee Management System