Junglewise Threat Intelligence

CVE-2026-12129: CodeAstro Human Resource Management System stored XSS in To-Do List

CVE-2026-12129 · Severity: low · CVSS 3.5 · Published 2026-06-12

Vendors: CodeAstro.

Executive brief

A security vulnerability exists in the CodeAstro Human Resource Management System, a software platform used for managing employee data and administrative tasks. An attacker can inject malicious scripts into the 'To-Do List' feature on the dashboard. When other users or administrators view the dashboard, these scripts execute automatically, which could lead to unauthorized actions being performed in their session or the theft of sensitive information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in CodeAstro Human Resource Management System 1.0. The flaw is located in the /dashboard/add_todo endpoint (specifically within the Dashboard Interface component) due to insufficient sanitization of the 'todo_data' parameter. An authenticated attacker can submit a POST request containing a malicious JavaScript payload (e.g., using an SVG onload event). This payload is stored in the application's database and executes in the context of any user who subsequently views the dashboard or the To-Do List section. This can be used to hijack user sessions or perform unauthorized actions on behalf of other users. A public exploit is available.

Affected products

  • CodeAstro Human Resource Management System 1.0

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory

References