CVE-2025-67102

Published
View on NVD ↗
CVSS v3
7.6
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands via the entity parameter.

Leave and Overtime Management System
GitHubGitHub
407