CVE-2026-9417

A vulnerability was detected in code-projects Employee Management System 1.0. Affected is an unknown function of the file /myprofileup.php. Performing a manipulation of the argument ID results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.

Credits

SSL_Seven_Security_Lab_WangZhiQiang_ZhanXiuChen (VulDB User)

References