CVE-2022-3493

LOW

SourceCodester Human Resource Management System 1.0 - Cross-Site Scripting via Employee Name Fields

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as problematic, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the component Add Employee Handler. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-210773 was assigned to this vulnerability.

References (1)

Core 1
Core References
Permissions Required, Third Party Advisory
https://vuldb.com/?id.210773

Scores

CVSS v3 3.5
EPSS 0.0033
EPSS Percentile 24.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-707
Status published
Products (1)
oretnom23/human_resource_management_system 1.0
Published Oct 13, 2022
Tracked Since Feb 18, 2026