CVE-2025-26258 β€” Cross-site Scripting in Employee Management System

Severity
6.1MEDIUMNVD
EPSS
0.0%
top 93.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 26

Description

Sourcecodester Employee Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via 'Add Designation.'

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

πŸ”΄Vulnerability Details

2
CVEList
CVE-2025-26258: Sourcecodester Employee Management System v1β†—2025-09-26
β–Ά
GHSA
GHSA-h889-572v-9cfg: Sourcecodester Employee Management System v1β†—2025-09-26
β–Ά
CVE-2025-26258 β€” Cross-site Scripting | cvebase