PT-2026-42996 · Code Projects · Employee Management System
Ssl_Seven_Security_Lab_Wangzhiqiang_Zhanxiuchen
·
Published
2026-05-25
·
Updated
2026-05-25
·
CVE-2026-9418
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
A flaw has been found in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /changepassemp.php. Executing a manipulation of the argument ID can lead to cross site scripting. The attack may be performed from remote. The exploit has been published and may be used.
Exploit
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Employee Management System