CVE-2026-11491: Codeastro Human Resource Management System
Low severity, CVSS 2.4. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function of the file /notice/All_notice of the component Notice Board Management. Such manipulation of the argument Notice Title with the input <svg onload="alert('Stored XSS Triggered by Ashik Mohamed')"> as part of POST leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Affected products
- Codeastro Human Resource Management System: version 1.0 only
Published 2026-06-08. Last modified 2026-07-23.