A security vulnerability has been detected in code-projects Employee Leave Managing System 1.0. Affected is an unknown function of the file /EmpManageSys/editaction.php of the component Employee Profile Update. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
code-projects Employee Leave Managing System Employee Profile Update editaction.php cross site scripting
Problem type
Affected products
code-projects
1.0 - AFFECTED
References
https://vuldb.com/vuln/397122
https://vuldb.com/vuln/397122/cti
https://vuldb.com/cve/CVE-2026-82622
https://vuldb.com/submit/893185
https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Stored%20Cross-Site%20Scripting%20(XSS)%20in%20Employee%20Leave%20Managing%20System%20PHP%20name%20Parameter.md
https://code-projects.org/
GitHub Security Advisories
GHSA-xq28-2cvr-v7h6
A security vulnerability has been detected in code-projects Employee Leave Managing System 1.0....
https://github.com/advisories/GHSA-xq28-2cvr-v7h6A security vulnerability has been detected in code-projects Employee Leave Managing System 1.0. Affected is an unknown function of the file /EmpManageSys/editaction.php of the component Employee Profile Update. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
https://nvd.nist.gov/vuln/detail/CVE-2026-82622
https://code-projects.org
https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Stored%20Cross-Site%20Scripting%20(XSS)%20in%20Employee%20Leave%20Managing%20System%20PHP%20name%20Parameter.md
https://vuldb.com/cve/CVE-2026-82622
https://vuldb.com/submit/893185
https://vuldb.com/vuln/397122
https://vuldb.com/vuln/397122/cti
https://github.com/advisories/GHSA-xq28-2cvr-v7h6
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-82622Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-82622",
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"dateUpdated": "2026-08-31T06:00:12.294Z",
"dateReserved": "2026-08-30T08:01:56.184Z",
"datePublished": "2026-08-31T06:00:12.294Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB",
"dateUpdated": "2026-08-31T06:00:12.294Z"
},
"title": "code-projects Employee Leave Managing System Employee Profile Update editaction.php cross site scripting",
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been detected in code-projects Employee Leave Managing System 1.0. Affected is an unknown function of the file /EmpManageSys/editaction.php of the component Employee Profile Update. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used."
}
],
"affected": [
{
"vendor": "code-projects",
"product": "Employee Leave Managing System",
"cpes": [
"cpe:2.3:a:code-projects:employee_leave_managing_system:*:*:*:*:*:*:*:*"
],
"modules": [
"Employee Profile Update"
],
"versions": [
{
"version": "1.0",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "Cross Site Scripting",
"cweId": "CWE-79",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "Code Injection",
"cweId": "CWE-94",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/vuln/397122",
"name": "VDB-397122 | code-projects Employee Leave Managing System Employee Profile Update editaction.php cross site scripting",
"tags": [
"vdb-entry",
"technical-description"
]
},
{
"url": "https://vuldb.com/vuln/397122/cti",
"name": "VDB-397122 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
]
},
{
"url": "https://vuldb.com/cve/CVE-2026-82622",
"name": "CVE-2026-82622 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://vuldb.com/submit/893185",
"name": "Submit #893185 | code-projects Employee Leave Managing System In PHP With Source Code 1,0 Cross Site Scripting",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Stored%20Cross-Site%20Scripting%20(XSS)%20in%20Employee%20Leave%20Managing%20System%20PHP%20name%20Parameter.md",
"tags": [
"exploit"
]
},
{
"url": "https://code-projects.org/",
"tags": [
"product"
]
}
],
"metrics": [
{},
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
"baseScore": 3.5,
"baseSeverity": "LOW"
}
},
{
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
"baseScore": 3.5,
"baseSeverity": "LOW"
}
},
{
"cvssV2_0": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR",
"baseScore": 4
}
}
],
"timeline": [
{
"time": "2026-08-30T00:00:00.000Z",
"lang": "en",
"value": "Advisory disclosed"
},
{
"time": "2026-08-30T02:00:00.000Z",
"lang": "en",
"value": "VulDB entry created"
},
{
"time": "2026-08-30T10:07:03.000Z",
"lang": "en",
"value": "VulDB entry last update"
}
],
"credits": [
{
"lang": "en",
"value": "AhmadMarzook (VulDB User)",
"type": "reporter"
}
],
"tags": [
"x_freeware"
]
}
}
}