github.comexploit
https://github.com/sorcha-l/cve/blob/main/Employee%20Management%20System%20by%20rems%20has%20xss.md CVE-2025-1905
MEDIUM
SourceCodester Employee Management System employee.php cross site scripting
Record summary
CVE-2025-1905 has a selected CVSS score of 5.1 (medium).
Description
A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. This affects an unknown part of the file employee.php. The manipulation of the argument Full Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 4, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Employee Management SystemBrowse SourceCodester / Employee Management System | CVE List | 1.0 | affected |
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-1905 VDB-298425 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.298425 VDB-298425 | SourceCodester Employee Management System employee.php cross site scriptingvdb entryTechnical description
https://vuldb.com/?id.298425 Submit #508301 | https://www.sourcecodester.com/php/17847/employee-management-sys Employee Management System 1.0 Cross Site Scripting (XSS)Third-party advisory
https://vuldb.com/?submit.508301 sourcecodester.comproduct
https://www.sourcecodester.com/