---
id: CVE-2026-105188
title: >-
  A vulnerability was found in code-projects Human Resource Management System
  1.0
summary: >-
  A vulnerability was found in code-projects Human Resource Management System
  1.0. Affected by this vulnerability is an unknown functionality of the file
  /views/admin/liveEventHistory.php of the component Live Event History. The
  manipulati…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: code-projects
product: Human Resource Management System
affected:
  - human_resource_management_system 1.0
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T16:17:10.777'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105188'
references:
  - url: 'https://code-projects.org/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/user-attachments/assets/f4902bfb-fc8e-4e4c-8ef8-01fde7c51038
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-105188'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/971660'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413425'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413425/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-05T15:10:14.435777Z'
epss: 0.00199
epssPercentile: 0.08758
ingestedAt: '2026-10-05T05:13:06.580Z'
---

## Overview

A vulnerability was found in code-projects Human Resource Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /views/admin/liveEventHistory.php of the component Live Event History. The manipulation of the argument eventSubject results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
