Junglewise Threat Intelligence

CVE-2026-9418: code-projects Employee Management System XSS in changepassemp.php

CVE-2026-9418 · Severity: medium · CVSS 4.3 · Published 2026-05-25

Technologies: Code-Projects Employee Management System. Vendors: Code-Projects.

Executive brief

A security vulnerability exists in the code-projects Employee Management System, a web application used for managing staff records. An attacker can send a specially crafted link to a user that, when clicked, executes malicious scripts in their web browser. This could allow the attacker to steal login sessions, perform actions on behalf of the user, or display fraudulent information on the site.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in code-projects Employee Management System 1.0 within the /changepassemp.php component. The root cause is the improper neutralization of the 'id' GET parameter, which is embedded into HTML navigation link attributes (such as href) without adequate escaping. A remote attacker can exploit this by crafting a malicious URL containing a JavaScript payload (e.g., using event handlers like OnMoUsEoVeR). If a victim visits the link, the payload executes in the context of their browser session, potentially leading to session hijacking or account takeover. A public exploit (PoC) has been disclosed.

Affected products

  • code-projects Employee Management System 1.0

Timeline

  • 2026-05-25: disclosed: Vulnerability published and exploit released.
  • 2026-05-25: advisory

References

Related threats