PT-2025-13241 · Code Projects · Payroll Management System

Samlo

·

Published

2025-03-27

·

Updated

2025-05-14

·

CVE-2025-2854

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Payroll Management System version 1.0
Description A critical issue was found in the Payroll Management System. The problem affects an unknown functionality of the file update employee.php. The manipulation of the emp type argument leads to SQL injection. This issue can be exploited remotely.
Recommendations For code-projects Payroll Management System version 1.0, consider restricting access to the update employee.php file until a patch is available. As a temporary workaround, avoid using the emp type argument in the affected functionality to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-2854

Affected Products

Payroll Management System