CVE-2026-11491 | CodeAstro Human Resource Management System 1.0 Notice Board Management /notice/All_notice Notice Title cross site scripting
A vulnerability classified as problematic was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function of the file /notice/All_notice of the component Notice Board Management. Such manipulation of the argument Notice Title with the input <svg onload="alert('Stored XSS Triggered by Ashik Mohamed')"> as part of POST leads to cross site scripting.
This vulnerability is referenced as CVE-2026-11491. It is possible to launch the attack remotely. Furthermore, an exploit is available.