CNNVD-202508-175 Information
Aug 03, 2025
cve
CNNVD ID
CNNVD-202508-175
Related CVE
- CNNVD Published: 2025-08-03
Description (Chinese)
Code-Projects Human Resource Integrated System是Code-Projects开源的一个人力资源管理系统。 Code-Projects Human Resource Integrated System 1.0版本存在代码注入漏洞,该漏洞源于文件/insert-and-view/action.php中参数content的错误操作导致跨站脚本。
Description (English)
Code-Projects Human Resources Management Systems is an open-source human resources management system for Code-Projects. There is a code-injection loophole in version 1.0 of Code-Projects Human Resources.
Hazard Level
Critical
Vulnerability Type
代码注入
Affected Vendor
Code-Projects
Published
2025-08-03
Last Modified
2026-02-24
References
https://vuldb.com/?ctiid.318600 https://code-projects.org/ https://github.com/shenxianyuguitian/hris-vuln-XSS/blob/main/README.md https://vuldb.com/?submit.626792 https://vuldb.com/?id.318600 https://access.redhat.com/security/cve/cve-2025-8501
Share on: