Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22991 | Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searcstate' parameter in/state.php. |
Mon, 04 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oretnom23
Oretnom23 human Resource Management System |
|
| CPEs | cpe:2.3:a:oretnom23:human_resource_management_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Oretnom23
Oretnom23 human Resource Management System |
|
| Metrics |
cvssV3_1
|
Tue, 29 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Jul 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searcstate' parameter in/state.php. | |
| Title | Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-07-29T13:03:09.159Z
Reserved: 2025-04-16T08:38:17.111Z
Link: CVE-2025-40685
Updated: 2025-07-29T12:59:02.858Z
Status : Analyzed
Published: 2025-07-29T13:15:26.897
Modified: 2025-08-04T20:59:22.280
Link: CVE-2025-40685
No data.
OpenCVE Enrichment
No data.
EUVD