---
id: CVE-2025-11124
title: A vulnerability has been found in code-projects Project Monitoring System 1.0
summary: >-
  A vulnerability has been found in code-projects Project Monitoring System 1.0.
  Affected is an unknown function of the file
  /onlineJobSearchEngine/postjob.php. Such manipulation of the argument
  txtapplyto leads to cross site scripting. Th…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: fabian
product: project_monitoring_system
affected:
  - project_monitoring_system = 1.0
published: '2025-09-28'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T09:10:00.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11124'
references:
  - url: 'https://code-projects.org/'
    label: cna@vuldb.com
  - url: 'https://github.com/asd1238525/cve/blob/main/xss4.md'
    label: cna@vuldb.com
  - url: 'https://github.com/asd1238525/cve/blob/main/xss4.md#poc'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.326205'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.326205'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.664309'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00286
epssPercentile: 0.19391
ingestedAt: '2026-10-09T09:31:00.976Z'
---

## Overview

A vulnerability has been found in code-projects Project Monitoring System 1.0. Affected is an unknown function of the file /onlineJobSearchEngine/postjob.php. Such manipulation of the argument txtapplyto leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

## Affected

- `project_monitoring_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
