ZeroHour

CVE-2025-26158

PoC
CVSS 3.1
5.6 medium
EPSS
<1%p25
Published
()
Modified
Description

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Attendance Management System V1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the department parameter.

Vendors
kashipara
Products
online attendance management system
Weakness
CWE-79
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L

In the news

No ingested article mentions this CVE yet.