Vulnerabilities
Vulnerable Software
Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'employeeid' parameter in/detailview.php.
CVSS Score
6.1
EPSS Score
0.0
Published
2025-07-29
SQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, create, update and delete databases via the “city” and “state” parameters in the /controller/ccity.php endpoint.
CVSS Score
9.8
EPSS Score
0.0
Published
2025-07-29
Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searccity' parameter in /city.php.
CVSS Score
6.1
EPSS Score
0.0
Published
2025-07-29
Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searccountry' parameter in/country.php.
CVSS Score
6.1
EPSS Score
0.0
Published
2025-07-29
Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searcstate' parameter in/state.php.
CVSS Score
6.1
EPSS Score
0.0
Published
2025-07-29
A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.
CVSS Score
5.4
EPSS Score
0.001
Published
2024-05-30
A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.
CVSS Score
9.8
EPSS Score
0.005
Published
2024-05-30
Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.
CVSS Score
8.8
EPSS Score
0.002
Published
2024-05-14
Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.
CVSS Score
5.9
EPSS Score
0.0
Published
2024-05-14
Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.
CVSS Score
4.3
EPSS Score
0.002
Published
2024-05-14


Contact Us

Shodan ® - All rights reserved