Junglewise Threat Intelligence

CVE-2026-12130: CodeAstro Human Resource Management System stored XSS in Projects Management Page

CVE-2026-12130 · Severity: low · CVSS 3.5 · Published 2026-06-12

Vendors: CodeAstro.

Executive brief

A security vulnerability exists in the CodeAstro Human Resource Management System, a software platform used for managing employee data and company projects. An attacker can inject malicious scripts into project titles, which then run automatically when other staff members view the project management pages. This could allow an attacker to perform unauthorized actions in the context of another user's session or redirect users to malicious websites.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in CodeAstro Human Resource Management System 1.0 within the Projects Management Page. The root cause is improper sanitization of the 'protitle' argument in the /Projects/Add_Projects file. A remote attacker with low-level privileges can submit a project containing a malicious JavaScript payload. This payload is persistently stored in the database and executes in the browser of any user who visits the 'All Projects' or project view pages. While an exploit has been publicly released, no official patch is currently documented.

Affected products

  • CodeAstro Human Resource Management System 1.0

Timeline

  • 2026-06-12: disclosed: Vulnerability disclosed and exploit released to the public.
  • 2026-06-12: advisory

References