Security Advisory

CVE-2025-40685

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-07-29 12:12:44
Last updated 2025-07-29 13:03:09
Assigner INCIBE
State PUBLISHED

Description

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victims browser by sending a malicious URL through the searcstate parameter in/state.php.