Executive brief
A security vulnerability exists in the CodeAstro Human Resource Management System, a platform used for managing employee records and internal communications. An attacker with administrative or high-level access can inject malicious scripts into the 'Notice Title' field of the Notice Board. If another user views the notice board, these scripts could execute in their browser, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in CodeAstro Human Resource Management System 1.0 within the Notice Board Management component. The issue is located in the /notice/All_notice file, where the 'Notice Title' POST argument is improperly neutralized before being stored and rendered. An attacker with high privileges (PR:H) can submit a malicious payload, such as an SVG onload event, which executes in the context of other users' browsers when they view the notice board. This vulnerability is tracked as CVE-2026-11491 and requires user interaction (UI:R) to trigger the script execution.
Affected products
- CodeAstro Human Resource Management System 1.0
Timeline
- 2026-06-08: disclosed
- 2026-06-08: advisory