Reflected Cross-Site Scripting in Human Resource Management System by Incibe
CVE-2025-40686
4.8MEDIUM
Key Information:
- Vendor
- CVE Published:
- 29 July 2025
What is CVE-2025-40686?
A reflected cross-site scripting (XSS) vulnerability has been identified in the Human Resource Management System version 1.0. This security flaw allows attackers to inject and execute arbitrary JavaScript code within the context of the victim's browser. By manipulating the 'employeeid' parameter in the 'detailview.php' page, an attacker can craft a malicious URL that, when accessed by a user, executes harmful scripts. This exploitation could lead to unauthorized actions or data exposure.
Affected Version(s)
Human Resource Management System 1.0