CVE-2026-105188

medium

Description

A vulnerability was found in code-projects Human Resource Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /views/admin/liveEventHistory.php of the component Live Event History. The manipulation of the argument eventSubject results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used.

References

https://vuldb.com/vuln/413425/cti

https://vuldb.com/vuln/413425

https://vuldb.com/submit/971660

https://vuldb.com/cve/CVE-2026-105188

https://github.com/user-attachments/assets/f4902bfb-fc8e-4e4c-8ef8-01fde7c51038

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-92248

https://code-projects.org/

Details

Source: Mitre, NVD

Published: 2026-10-05

Updated: 2026-10-06

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 3.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Severity: Low

CVSS v4

Base Score: 5.1

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00199