CVE-2025-26158 Information

Description

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Attendance Management System V1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the department parameter.

Reference

https://github.com/rtnthakur/CVE/blob/main/Kashipara/README.md

CNNVD-202511-1787 (Published: 2025-11-15)

Share on: