Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 09 Jun 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sourcecodester
Sourcecodester human Resource Management System |
|
| Vendors & Products |
Sourcecodester
Sourcecodester human Resource Management System |
Mon, 08 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Jun 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function of the file /notice/All_notice of the component Notice Board Management. Such manipulation of the argument Notice Title with the input <svg onload="alert('Stored XSS Triggered by Ashik Mohamed')"> as part of POST leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. | |
| Title | CodeAstro Human Resource Management System Notice Board Management All_notice cross site scripting | |
| First Time appeared |
Codeastro
Codeastro human Resource Management System |
|
| Weaknesses | CWE-79 CWE-94 |
|
| CPEs | cpe:2.3:a:codeastro:human_resource_management_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Codeastro
Codeastro human Resource Management System |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-08T16:32:27.215Z
Reserved: 2026-06-07T10:13:37.591Z
Link: CVE-2026-11491
Updated: 2026-06-08T12:59:54.635Z
Status : Deferred
Published: 2026-06-08T07:16:26.663
Modified: 2026-06-08T14:57:14.757
Link: CVE-2026-11491
No data.
OpenCVE Enrichment
Updated: 2026-06-09T08:57:34Z