K4ptor/itsourcecode-Payroll-Management-System-V1.0-SQL-Injection

K4ptor/itsourcecode-Payroll-Management-System-V1.0-SQL-Injection

Releases0
Attackers can exploit this SQL injection vulnerability to no unauthorized database access, sensitive data leakage, data tampering, comprehensive system control, and even service interruption, posing a serious threat to system security and business continuity.

CVE History

CVEPublishedCVSS v3CVSS v2
7.3 HIGH7.5 HIGH

A security flaw has been discovered in itsourcecode Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /manage_user.php of the component Parameter Handler. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.