Junglewise Threat Intelligence

CVE-2026-82622: code-projects Employee Leave Managing System XSS in employee profile

CVE-2026-82622 · Severity: low · CVSS 3.5 · Published 2026-08-31

Vendors: Code-Projects.

Executive brief

code-projects Employee Leave Managing System is a free open-source HR application for managing employee leave requests and profile information. A flaw in the employee profile update feature allows attackers to inject malicious scripts through the Name field, which could be used to steal employee or administrator credentials, modify company records, or launch attacks against other system users.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Employee Profile Update component (file /EmpManageSys/editaction.php) due to insufficient input sanitization on the Name parameter. An authenticated user or attacker with network access can inject arbitrary JavaScript code through the Name field that will be stored in the database and executed in the browsers of any user viewing the modified employee profile. The vulnerability is remotely exploitable and has been publicly disclosed. A patch or version update is recommended if available from the vendor.

Affected products

  • code-projects Employee Leave Managing System 1.0

Timeline

  • 2026-08-31: disclosed
  • other: Publicly disclosed exploit available

References