Itsourcecode · Sourcecodester Employee Management System · CVE-2025-7126
Name of the Vulnerable Software and Affected Versions:
itsourcecode Employee Management System versions up to 1.0
Description:
A critical issue has been found in the itsourcecode Employee Management System. The problem affects some unknown functionality of the file /admin/adminprofile.php. The manipulation of the `AdminName` argument leads to SQL injection. This issue can be exploited remotely.
Recommendations:
For itsourcecode Employee Management System versions up to 1.0, consider updating to a version that fixes this issue, however at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the /admin/adminprofile.php file to minimize the risk of exploitation. Avoid using the `AdminName` argument in the affected file until the issue is resolved.